is there anyway to setup something on a dashboard that will tell me if a service on a remote centos box goes down.
I run arkime on a centos8 box and i want a dashboard in splunk that will show me the status of the services
arkimecaprute.service
arkimeviewer.service
elasticsearch.service
is this possible?
Are these services regularly logging? If you ingest the logs into splunk, you can search for when each service last logged a message and use that to determine if the service is up (and logging) or not.
the only way the service logs is if i use a cron job and when i tried that i realized the UF will only forward if the log has changed which is good but not in this instance since only 1 word really changes and does not always trigger the UF to read it. This is a sort of solution but i was wondering if there was a better one out there that i was just not aware of.