Getting Data In

monitoring splunk server(s)

mflamerich
Explorer

Hi,
I would like to know if there is a 'best practice' document around the topic of monitoring and alerting about a splunk server health.
What would be the recommendation to implement a monitor on "splunkd" ?
I have alerts in case a forwarder is sending less than expected, but how do I send alerts if splunkd has crashed?
I would like to know if there is a splunk solution for this kind of alerting, so I will not have to install another monitor (Nagios, BigBrother) to monitor splunk.

Tags (1)
1 Solution

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

View solution in original post

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...