Getting Data In

monitoring splunk server(s)

mflamerich
Explorer

Hi,
I would like to know if there is a 'best practice' document around the topic of monitoring and alerting about a splunk server health.
What would be the recommendation to implement a monitor on "splunkd" ?
I have alerts in case a forwarder is sending less than expected, but how do I send alerts if splunkd has crashed?
I would like to know if there is a splunk solution for this kind of alerting, so I will not have to install another monitor (Nagios, BigBrother) to monitor splunk.

Tags (1)
1 Solution

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

View solution in original post

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...