Splunk Enterprise

Report on Log Sources not sending logs to Splunk [Active Passive setup with only one host expected to send logs

SunilMaharishi
Path Finder

Dear all ,

 

Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .

Only one set of hosts will send  logs. 

We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.

We do not want to report as alert if any one active/passive host pair has  sent logs in last 24 hours.

I.e. if both active passive devices stop sending the logs we need to report.

 

any help will be appreciated

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Finding something that is not there is not Splunk's strong suit.  See this blog entry for a good write-up on it.

https://www.duanewaddle.com/proving-a-negative/

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...