Splunk Enterprise

Report on Log Sources not sending logs to Splunk [Active Passive setup with only one host expected to send logs

suny198
New Member

Dear all ,

 

Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .

Only one set of hosts will send  logs. 

We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.

We do not want to report as alert if any one active/passive host pair has  sent logs in last 24 hours.

I.e. if both active passive devices stop sending the logs we need to report.

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How do you know which host is paired with which?

0 Karma

suny198
New Member

I have lookup with active and passive asset listed with their respective IP addresses listed in CSV sheet .

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What data do you have in your lookup? What is returned when you look up each side of the active and passive pair? For example, do you get both addresses or an identifier unique for the pair?

0 Karma

suny198
New Member
0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Cloud Platform 9.1.2308?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2308! Analysts can ...

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...