Splunk Search

What would you include on a Splunk "daily checklist"?

nnimbe
Path Finder

Hi Team,

I am new to Splunk and want to create a Splunk daily checklist which includes,
total number of devices reporting, devices not reported since last 1 day, Splunk performance usage, Splunk data indexed per day, Splunk EPS, new devices reported since last 1 day (or in case of any other important parameter to monitor)

Can anybody help me with the list of commands which will helpful for the analysts to perform on day to day basis and can be used as Splunk checklist on daily basis, (or if you have any existing checklist then please share).

The idea is to monitor the Splunk infra on daily basis wrt all the parameters and ensure Splunk will be running up and fine without any issue.

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

Use the DMC, and also check out the health checks. You can customize these for a particular set of Splunk features. Check here for more information : http://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Customizehealthcheck

View solution in original post

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Use the DMC, and also check out the health checks. You can customize these for a particular set of Splunk features. Check here for more information : http://docs.splunk.com/Documentation/Splunk/6.6.3/DMC/Customizehealthcheck

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Have you looked into the Monitoring Console yet? This gives you a great idea about the health of your Splunk systems

https://docs.splunk.com/Documentation/Splunk/6.6.2/DMC/DMCoverview

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...