Dashboards & Visualizations

Monitor Indexing on Dashboard

indikaw
Explorer

Hi All,

I have few questions to ask if you can help me.
My Splunk server only has 3 default indexes which are internal, main and audit. I am trying to create a dashboard so I can monitor the indexing activity at a glass everyday morning.

I still can't get the right search string to do this. Can you please let me know how to search for the indexing? So I can put that search in to a dashbord panel. Also then I can set that up for every 24 hours and every morning I can load the dashbord and have an idea about indexing.

Second question is, as same as above how do I get the indexing errors on to a dashboard.

Your help is more that appreciated.

Thanks
Indika

Tags (3)
0 Karma

Drainy
Champion

Pretty wide question.

My first answer would be, use Splunk SoS to check the health and for problems of your indexes. Use the deployment monitor to monitor activity. In reality your indexes should be configured in such a way that you don't need to continually monitor your environment like this. If you do need to then you need to sit down and make sure everything is correctly configured and that your licence meets your needs.
If you really need to then just pull the searches out of the SoS app, they cover everything you need to know (why re-invent the wheel! 🙂 ). If you had anything more specific then just reply back with more detail.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...