Splunk Enterprise

Report on Log Sources not sending logs to Splunk [Active Passive setup with only one host expected to send logs

suny198
New Member

Dear all ,

 

Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .

Only one set of hosts will send  logs. 

We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.

We do not want to report as alert if any one active/passive host pair has  sent logs in last 24 hours.

I.e. if both active passive devices stop sending the logs we need to report.

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

How do you know which host is paired with which?

0 Karma

suny198
New Member

I have lookup with active and passive asset listed with their respective IP addresses listed in CSV sheet .

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What data do you have in your lookup? What is returned when you look up each side of the active and passive pair? For example, do you get both addresses or an identifier unique for the pair?

0 Karma

suny198
New Member
0 Karma