Splunk Search

Search for peers with status=down

pc1
Path Finder

What search can I do to find peers with status=down. Looking to form an alert when this happens but can't find it within a search. 

0 Karma
1 Solution

somesoni2
Revered Legend

Splunk Monitoring console (formally known as DMC) has alert "DMC Alert - Search Peer Not Responding" which does the same thing. It basically runs following search:

 

| rest splunk_server=local /services/search/distributed/peers/
| where status!="Up"
| fields peerName, status
| rename peerName as Instance, status as Status

 

View solution in original post

net_id
New Member

Anyone coming here should know that in 9.2.0.1 this does not work any more.
Look at dmc_instances_view_default_search macro for how the monitoring console does it now.

0 Karma

somesoni2
Revered Legend

Splunk Monitoring console (formally known as DMC) has alert "DMC Alert - Search Peer Not Responding" which does the same thing. It basically runs following search:

 

| rest splunk_server=local /services/search/distributed/peers/
| where status!="Up"
| fields peerName, status
| rename peerName as Instance, status as Status

 

pc1
Path Finder

Yup, found this preexisting alert and was able to edit the Actions on it to integrate with the Slack Notifications add-on. Runs every 5 minutes to check if the server is down so this works perfectly for me. Thanks for the help!

0 Karma

Stefanie
Builder

Are you looking for hosts with forwarders installed that havent reported to Splunk in some time?

You can use the Monitoring Console to view that.  To view the missing hosts, you can click on the Forwarders tab and then Forwarders: Deployment.

For an alert, go to the Monitoring Console -> Settings -> Alerts Setup. There is an alert named DMC Alert - Missing Forwarders.

Note: A forwarder shows a status of "missing" if it has not connected to indexers within 15 minutes

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...