Splunk Search

Can you help me monitor httpd process through Splunk on a Linux Machine?

ssatti
New Member

Greetings all,

I want to monitor an "httpd" process for a Linux Machine, and if the process is down or not running, I need to shoot an alert.

Could you please help me with the search query for this?

Thanks in advance.

0 Karma

lakshman239
Influencer

You can install nix add on and enable the process monitoring scripted input. This gives you all active processed, including 'httpd'. on the server. You can then create a seach/alert when the process 'httpd' is down (not seen in the events coming from the add-on).

https://splunkbase.splunk.com/app/833/

0 Karma

lakshman239
Influencer

Did this help you resolve the issue?

0 Karma

ssatti
New Member

I already had Nix addon and enabled the process monitoring.
But Search/alert is not working as expected. could you please give me an example search. Thanks Lakshman

0 Karma

renjith_nair
Legend

@ssatti,
It would be helpful if you could provide some more details.
- Have you tried something ?
- Do you have the events about status already in splunk ? If not you have to start from pushing the status to splunk.
- If you have the events, how do they look like ? Any sample events?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...