Dashboards & Visualizations

Useful dashboards alerts for administrator

shahzadarif
Path Finder

I would like to know what reports / dashboards / alerts you've got setup to monitor the state of your Splunk infrastructure?
Right now I've a dashboard which gives me view of licence usage and log files indexed so I know my indexers are working. But there's nothing for let's say SHs. What search would be useful to give me a view of all my SHs are available for searching?
I should add I don't want to view this information in DMC because this dashboard would be run on a raspberry Pi so it must live on SHs.

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If youre not wanting to use the MC, you can easily take the searches out of the MC, and customize them to what you are looking for. The dash boards in the MC are meant to help understand, and to an extent, manage your distributed Splunk environment. There is plenty in there about SH, but your biggest points to monitor would be CPU, RAM, and search concurrency.

Adapting these prebuilt searches out of the MC would be easiest. Aside from this, you could look at the deprecated SoS App (Splunk on Splunk.) However, most of the searches used in that app were all adapted and put into the MC.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...