Splunk Enterprise

Monitor Splunks Internal Processes and Log Ingestion

celdridge1988
Engager

Hi All,

Currently running a distributed instance of Splunk on prem. Is there a way to monitor splunk manually through search rather than the DMC? The reason is because i would like to alert teams of faults (like an indexer not being seen by a cluster master etc.). I've also had an issue where we've not noticed where a data source has stopped ingesting, has anyone been able to successfully implement a search to detect when a log source stops ingesting?

All ideas are welcome! Thank you in advance 🙂

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
The Monitoring Console is a search head so you can create your own alerts there, if you wish. Just search the logs for the error condition of interest and save it as an alert.
---
If this reply helps you, Karma would be appreciated.
0 Karma

gjanders
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...