We have 8 windows servers, where splunk universal forwarder is installed and it will forward all the logs to splunk indexer servers and from splunk search header we can monitor all the logs related to the servers.
In some instances we have seen, the windows servers sometime goes into hang state, but we don't have any alert mechanism to get notified on the same. So kindly help us to understand how to accommodate the particular monitoring through splunk.
Below is the splunk architecture for our environment: