Hi,
I would like to know if there is a 'best practice' document around the topic of monitoring and alerting about a splunk server health.
What would be the recommendation to implement a monitor on "splunkd" ?
I have alerts in case a forwarder is sending less than expected, but how do I send alerts if splunkd has crashed?
I would like to know if there is a splunk solution for this kind of alerting, so I will not have to install another monitor (Nagios, BigBrother) to monitor splunk.
Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).
Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.
You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk
Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).
Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.
You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk