Alerting

Alert for "Problem replicating config (bundle)"

hartfoml
Motivator

I would like to know when a web:ui user get a bundle replication error. does anyone know where can I look to setup an alert so that I get an email every time this error is shown to the users?

Tags (2)
0 Karma

rtadams89
Contributor

You can find these events in the _internal index.

hartfoml
Motivator

Sorry I am on version 4.3.1 and these logs are not recorded in any index that I can find.

0 Karma

rtadams89
Contributor

Try searching for:

index=_internal component=DistributedPeerManager

This should show you all the bundle replication events. You can further refine this to:

index=_internal component=DistributedPeerManager "replication was unsuccessful"

Which will show you the failures.

0 Karma

hartfoml
Motivator

ya thanks, Thanks was the first place I looked but could not find them in there. Thanks anyway.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...