Monitoring Splunk
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Monitoring Splunk
via SplunkWeb
Splunk has built-in saved searches that let you monitor its performance. Run any of these saved searches to receive metrics on Splunk:
- Daily indexing volume
- Errors in the last 24 hours
- Kbps indexed per hour last 24 hours
- Messages by minute last 3 hours
- Splunk errors last 24 hours
You can also add any saved search to your dashboard, if you want metrics available on your SplunkWeb landing page.
This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4 View the Article History for its revisions.