Splunk Enterprise Security
Highlighted

How to write a search to alert if our Splunk Enterprise Security search head goes down?

Path Finder

Hi ,

We are looking to create an alert if for any reason a search head went down. This is for our Splunk Enterprise Security search head, since we have only one search head is available in our environment, we are looking to create an alert if the ES search head goes down.

Thanks

0 Karma
Highlighted

Re: How to write a search to alert if our Splunk Enterprise Security search head goes down?

Ultra Champion

We use - | rest splunk_server=local /services/search/distributed/peers/ | where status!="Up" | fields peerName, status | rename peerName as Instance, status as Status

0 Karma
Highlighted

Re: How to write a search to alert if our Splunk Enterprise Security search head goes down?

Path Finder

This is for search peers correct? can we use the same for search head,as we are looking for SH.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.