Alerting

Alert for "Problem replicating config (bundle)"

hartfoml
Motivator

I would like to know when a web:ui user get a bundle replication error. does anyone know where can I look to setup an alert so that I get an email every time this error is shown to the users?

Tags (2)
0 Karma

rtadams89
Contributor

You can find these events in the _internal index.

hartfoml
Motivator

Sorry I am on version 4.3.1 and these logs are not recorded in any index that I can find.

0 Karma

rtadams89
Contributor

Try searching for:

index=_internal component=DistributedPeerManager

This should show you all the bundle replication events. You can further refine this to:

index=_internal component=DistributedPeerManager "replication was unsuccessful"

Which will show you the failures.

0 Karma

hartfoml
Motivator

ya thanks, Thanks was the first place I looked but could not find them in there. Thanks anyway.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...