This message originated from Cribl Community Slack.
Click here to view the original link.
I've poked around a bit in the #channel history and didn't find a direct answer to this, so forgive me if I missed it. What is the simplest, most direct way to observe when a node becomes disconnected from the leader, preferably when it has been disconnected for x consecutive minutes? We're ingesting Cribl Stream logs into Splunk. Is this information in those? If not, which server-side logs might contain this information?
Solved
What Is The Simplest, Most Direct Way To Observe When A Node Becomes Disconnected From The Leader, Preferably When It…
Best answer by fetaboy918
Have you tried to create an alert in Splunk to monitor the last event per server from Cribl Edge where you filter like, latest_time > 2h for eg? That's what we do anyway. You will catch log ingestion delay + possible disconnection.
Sign up
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
