Splunk Search

To check if service of endpoint starts back once stopped

DawoodKhanUlex
Engager

Hi Folks,

 

I am working on creating an alert for endpoint where we have to check if its service came up after it got stop during upgrade.

For eg: - Host A service stop and didnt came up for 3 days then an alert will be triggered.

Also we can compare on basis of filedname state=Stopped and state=Running, but host should be same

Please let me know if there is any way we can create alert for this scenario

Thanks,

Labels (1)
0 Karma

diogofgm
SplunkTrust
SplunkTrust

Have you tried something like this?

<your base search>
| stats last(state) AS state last(_time) AS _time by host service
| eval time_diff = now() - _time
| where (state="Stopped" AND time_diff > 259200)

 

 

------------
Hope I was able to help you. If so, some karma would be appreciated.
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...