Reporting

Server Up-time /down-time

bidahor13
Path Finder

hi, I'm still new to splunk
Question:
What search command do I need to run to create a report (or maybe an alert) showing if a server is up or down in real time?

Tags (3)
0 Karma

woodcock
Esteemed Legend

You need to forward some kind of log or KPI information into Splunk first. Then you search on that data. Let's assume it is Windows and you are sending perfmon into Splunk. You can track one of the KPIs or even the mere presence (or rather lack there of) of events arriving into Splunk to determine if the server is OK or not. Once you get a search working that correctly identifies servers that are down, you just save this search as an Alert and have it send you an email (or trap or whatever) whenever the search returns any results. More details are here:

http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Real-timeWindowsperformancemonitoring
http://www.splunk.com/view/SP-CAAAGYG

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...