Splunk Enterprise

Report on Log Sources not sending logs to Splunk [Active Passive setup with only one host expected to send logs

SunilMaharishi
Path Finder

Dear all ,

 

Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .

Only one set of hosts will send  logs. 

We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.

We do not want to report as alert if any one active/passive host pair has  sent logs in last 24 hours.

I.e. if both active passive devices stop sending the logs we need to report.

 

any help will be appreciated

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Finding something that is not there is not Splunk's strong suit.  See this blog entry for a good write-up on it.

https://www.duanewaddle.com/proving-a-negative/

---
If this reply helps you, an upvote would be appreciated.
0 Karma