Splunk Enterprise

Report on Log Sources not sending logs to Splunk [Active Passive setup with only one host expected to send logs

SunilMaharishi
Path Finder

Dear all ,

 

Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .

Only one set of hosts will send  logs. 

We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.

We do not want to report as alert if any one active/passive host pair has  sent logs in last 24 hours.

I.e. if both active passive devices stop sending the logs we need to report.

 

any help will be appreciated

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Finding something that is not there is not Splunk's strong suit.  See this blog entry for a good write-up on it.

https://www.duanewaddle.com/proving-a-negative/

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...