Alerting

How to configure a Heartbeat alert in a Search Head Cluster

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a Search Head Cluster with 3 SHs that sends alerts to an external system based on IBM NetCool.
Cluster deploys alerts between the three Search Heads and ensures that only one of them runs one alert.
My problem is to create a HeartBeat alert that runs on all the three Search Heads every period to be sure that the connection with IBM NetCool is OK.
How can I configure this alert to be executed at the same time on the three Search Heads?

Thank you.
Bye.
Giuseppe

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

I had an answer from Splunk Support: this is not possible.
Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

I had an answer from Splunk Support: this is not possible.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...