Dashboards & Visualizations

Monitor Indexing on Dashboard

indikaw
Explorer

Hi All,

I have few questions to ask if you can help me.
My Splunk server only has 3 default indexes which are internal, main and audit. I am trying to create a dashboard so I can monitor the indexing activity at a glass everyday morning.

I still can't get the right search string to do this. Can you please let me know how to search for the indexing? So I can put that search in to a dashbord panel. Also then I can set that up for every 24 hours and every morning I can load the dashbord and have an idea about indexing.

Second question is, as same as above how do I get the indexing errors on to a dashboard.

Your help is more that appreciated.

Thanks
Indika

Tags (3)
0 Karma

Drainy
Champion

Pretty wide question.

My first answer would be, use Splunk SoS to check the health and for problems of your indexes. Use the deployment monitor to monitor activity. In reality your indexes should be configured in such a way that you don't need to continually monitor your environment like this. If you do need to then you need to sit down and make sure everything is correctly configured and that your licence meets your needs.
If you really need to then just pull the searches out of the SoS app, they cover everything you need to know (why re-invent the wheel! 🙂 ). If you had anything more specific then just reply back with more detail.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...