Splunk Search

Splunk query for Forwarder , Indexer & SH restart

alexspunkshell
Contributor

Could someone please help me with the Splunk query to configure the alert if Forwarder, Indexer, or search head had restart?

@scelikok @soutamo @saravanan90 @thambisetty @ITWhisperer @gcusello @bowesmana   @to4kawa 

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is one way, maybe not the best one.

(index=_internal source=*splunkd.log (host=<YOUR SPLUNK NODES>) ((component=CMServiceThread "CMNotifyThread starting eloop") OR (component=ServerConfig "My GUID") OR (component=loader ("All pipelines finished." OR "Shutdown HTTPDispatchThread")) OR (component=ShutdownHandler "Shutting down splunkd"))) 
| transaction startswith="Shutting down splunkd" endswith="CMNotifyThread starting eloop" keeporphans=true keepevicted=true maxspan=10m
| sort host 
| streamstats reset_on_change=t sum(duration) as total_duration by host
| table _time, duration, total_duration, host, _raw
| eval duration=tostring(duration, "duration"), total_duration=tostring(total_duration, "duration")
| sort - _time

r. Ismo 

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is one way, maybe not the best one.

(index=_internal source=*splunkd.log (host=<YOUR SPLUNK NODES>) ((component=CMServiceThread "CMNotifyThread starting eloop") OR (component=ServerConfig "My GUID") OR (component=loader ("All pipelines finished." OR "Shutdown HTTPDispatchThread")) OR (component=ShutdownHandler "Shutting down splunkd"))) 
| transaction startswith="Shutting down splunkd" endswith="CMNotifyThread starting eloop" keeporphans=true keepevicted=true maxspan=10m
| sort host 
| streamstats reset_on_change=t sum(duration) as total_duration by host
| table _time, duration, total_duration, host, _raw
| eval duration=tostring(duration, "duration"), total_duration=tostring(total_duration, "duration")
| sort - _time

r. Ismo 

Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...