Splunk Enterprise

How to get Splunk alerting for Admins during on-call for free?

justynap_ldz
Path Finder

Hello Splunk Admins,

What solutions you use to get notified on mobile about internal Splunk issues in out of office hours?
I mean when e.g. splunkd goes down on indexers, data is not indexed anymore for any reason etc.
We need something free of charge. There is no other team except of us who needs to be notified about the issue.
I have heard about Splunk On Call solution but seems to be a bit complex. Anyone having any experience with it?
Hope to get some inspirations

Many greetings,
Justyna

Labels (2)
Tags (1)
0 Karma

kkong_splunk
Splunk Employee
Splunk Employee

(Full disclaimer: I'm the product manager for Splunk Mobile)

 

Splunk Mobile is a free app for Android or iOS that allows you to send push notifications to your phone based on the alerts in Enterprise. We actually had a user that we featured in our breakout session this year (PLA1488A) at .conf22 who used Mobile alerts to monitor his indexers, and was able to catch them going down on a weekend because of Splunk Mobile. 

You can configure alerts to be sent to a specific role, so if you already have a Splunk role setup for the folks on your team, you can send alerts to that role to receive them on mobile.

 

Documentation on getting started with Splunk Mobile is here:  https://docs.splunk.com/Documentation/Alerts/2.31.1/Alerts/GetStarted

Documentation on alerts specifically is here: https://docs.splunk.com/Documentation/Alerts/2.31.1/Alerts/SendAlerts

An overview of what Splunk Mobile looks like is here: https://www.youtube.com/watch?v=FOHwU00IVUE&ab_channel=Splunk

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...