Reporting

Server Up-time /down-time

bidahor13
Path Finder

hi, I'm still new to splunk
Question:
What search command do I need to run to create a report (or maybe an alert) showing if a server is up or down in real time?

Tags (3)
0 Karma

woodcock
Esteemed Legend

You need to forward some kind of log or KPI information into Splunk first. Then you search on that data. Let's assume it is Windows and you are sending perfmon into Splunk. You can track one of the KPIs or even the mere presence (or rather lack there of) of events arriving into Splunk to determine if the server is OK or not. Once you get a search working that correctly identifies servers that are down, you just save this search as an Alert and have it send you an email (or trap or whatever) whenever the search returns any results. More details are here:

http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Real-timeWindowsperformancemonitoring
http://www.splunk.com/view/SP-CAAAGYG

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...