Getting Data In

Can I be notified or alerted when Splunk goes down?

Dark_Ichigo
Builder

I want to be alerted when Splunkd goes down, how can I be notified?

0 Karma

ChrisG
Splunk Employee
Splunk Employee
0 Karma

Dark_Ichigo
Builder

I'm going to try creating a cronjob that can monitor Splunks status, but as from what I can see, there doesn't seem to be a perfect (risk free) way of doing this.

All other applications I have had to deploy in my lifetime had alarming capabilities for this purpose, as i kinda makes sense to have it.

0 Karma

Drainy
Champion

Well played sir, well played

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk for everything 😛

Drainy
Champion

But why use Splunk? You'd be better using a dedicated monitoring solution or some other cronjob to monitor for it

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Without a second system watching the first you won't notice the first system disappearing entirely, for instance when the machine goes boom or when someone takes Splunk down by using a sledgehammer...

0 Karma

Drainy
Champion

Why use another instance? Why not just do it the usual way of a cronjob checking every X minutes and firing an email if its down/trying to restart it?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If they both go down simultaneously you likely have a larger problem.

0 Karma

Dark_Ichigo
Builder

What if they both go down?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Just run a second Splunk on a tiny system somewhere (VM?) and have each monitor each other, raising hell when one goes missing.

0 Karma

Dark_Ichigo
Builder

Yes I understand that, but there should be an alarm that's raised and is able to notify Operations when its down...

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

When Splunk is down there is nothing Splunk can do because, well, it's down.

Dark_Ichigo
Builder

Yes but that means there isn't anything application specific ready to provide a user with alerts or notifications if and when Splunk does go down.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...