Monitoring Splunk

Monitoring Console Health Check does not run

harishbabum
Loves-to-Learn Lots

I am trying to run the Health check on the DMC.
Health check dashboard loads fine from the checklist.conf as per the default and local directory. Our splunk version is 9.3.0.
After clicking the start button it gets stuck at 0%. can i know what could be this issue?

Screenshot 2024-10-03 at 12.02.33 PM.png

Labels (1)
0 Karma

harishbabum
Loves-to-Learn Lots

I have the following setting in splunk_monitoring_console_assets.conf at location /etc/apps/splunk_monitoring_console/local/
[settings]
disabled = 0
I have same setting on the DMC, SH and indexers. everything works except DMC.

I have the following roles for the DMC. Should any other roles to be enabled.

Screenshot 2024-10-03 at 3.04.47 PM.png

0 Karma

harishbabum
Loves-to-Learn Lots

Thank you fro the quick reply.
It does not seem to run with individual category as well.

Screenshot 2024-10-03 at 12.48.33 PM.png

Screenshot 2024-10-03 at 12.49.49 PM.png

 Should we consider update health checks which take me to the Splunk Health Assistant Add-on which is archived?

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

I don't see an issue on my lab with the same version.

Screenshot 2024-10-03 at 11.38.47 AM.png

 The only reason I could think of is make sure there are no "unconfigured instances" on your monitoring console. Make sure you set this and apply changes as per this doc.
https://docs.splunk.com/Documentation/Splunk/9.3.1/DMC/Configureindistributedmode#Reset_server_roles...


Hope this helps and resolves.

0 Karma

harishbabum
Loves-to-Learn Lots

I have the following setting in splunk_monitoring_console_assets.conf at location /etc/apps/splunk_monitoring_console/local/
[settings]
disabled = 0
I have same setting on the DMC, SH and indexers. everything works except DMC.

I have the following roles for the DMC. Should any other roles to be enabled.

Screenshot 2024-10-03 at 3.30.52 PM.png

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

I believe there is something wrong on your DMC set up. Please only enable Distributed Mode on the monitoring console instead of search head and indexers. 

You can also try creating new health check item with some query and see if that works. 
/en-US/app/splunk_monitoring_console/monitoringconsole_check_list

I would encourage you to open a support case or on ondemand request.

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Does it run anything if you select individual category instead of all categories? If its running with fewer categories it could an issue related to load on the DMC to run all categories at once.

We had a similar kinda bug in the previous 8.2 versions but not on V9 as I see on my side.

 

 

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...