Splunk Search

IS there any script how we can check SPlunk agent is inactive in user server.

sahils
New Member

IS there any script or how we can check SPlunk agent is inactive in user server.
I received email or notification If SPlunk agent is not running on user servers.

Thanks,
Sahil

Tags (1)
0 Karma

sahils
New Member

Any update?

Thanks,
Sahil

0 Karma

lycollicott
Motivator

Do you maintain an up to date list of all the servers in your environment?

0 Karma

lycollicott
Motivator

You could write a script, but why don't you use the Monitoring Console? If you configured your Splunk to send emails then it can email you when a forwarder is missing, too.

Look at the bottom of this screen shot.

alt text

You can get started with the Monitoring Console here: https://docs.splunk.com/Documentation/Splunk/6.5.3/DMC/DMCoverview

sahils
New Member

Hello,

We are checking status in Deployment Server But If agent goes down We are not aware in which server or which application is impacted Is there any script , query or How we notify automatically tell us in Which server agent is down.

Thanks,
Sahil

0 Karma

lycollicott
Motivator

If the agent (UF) goes down then this will tell you it has stopped. That is what "missing" means.

0 Karma

andrey2007
Contributor

You can use Deployment server to manage agents(fowrwarders) which usually phoning home to deployemnet server
to know agent status you can use following search and configure alert for specific host

index=_internal (phonehome component=DC*) OR (component=DC:HandshakeReplyHandler) host=hostname
| sort _time
| table _time host log_level message

it is from https://answers.splunk.com/answers/208607/how-to-determine-if-forwarder-is-phoning-home-to-d.html

0 Karma

sahils
New Member

Thanks Andrey We are checking status in Deployment Server But If agent goes down We are not aware in which server or which application is impacted Is there any script , query or How we notify automatically tell us in Which server agent is down.

Regards,
Sahil

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can check if splunk is active by running splunk status on the CLI.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...