Dashboards & Visualizations

Useful dashboards alerts for administrator

shahzadarif
Path Finder

I would like to know what reports / dashboards / alerts you've got setup to monitor the state of your Splunk infrastructure?
Right now I've a dashboard which gives me view of licence usage and log files indexed so I know my indexers are working. But there's nothing for let's say SHs. What search would be useful to give me a view of all my SHs are available for searching?
I should add I don't want to view this information in DMC because this dashboard would be run on a raspberry Pi so it must live on SHs.

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If youre not wanting to use the MC, you can easily take the searches out of the MC, and customize them to what you are looking for. The dash boards in the MC are meant to help understand, and to an extent, manage your distributed Splunk environment. There is plenty in there about SH, but your biggest points to monitor would be CPU, RAM, and search concurrency.

Adapting these prebuilt searches out of the MC would be easiest. Aside from this, you could look at the deprecated SoS App (Splunk on Splunk.) However, most of the searches used in that app were all adapted and put into the MC.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...