icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Broken Hosts App for Splunk
SHA256 checksum (broken-hosts-app-for-splunk_404.tgz) 7b6411a3b3ad4340c8cea785eabc03b650d321df413aa1d8eaee276450efbe96 SHA256 checksum (broken-hosts-app-for-splunk_403.tgz) 0c187554b407df3296b91c7d3e7ee9445494ea4b0f29e8e96945d111d6da0500 SHA256 checksum (broken-hosts-app-for-splunk_402.tgz) dd4f1b9509ca819c1b5af0400f504f0db76ed5fd1569bb9b39301f6687fb74d0 SHA256 checksum (broken-hosts-app-for-splunk_336.tgz) 1eca643de55a82110966fd88842e4e23124359e77f9c6d118a2f41dbdff45cf6 SHA256 checksum (broken-hosts-app-for-splunk_335.tgz) ce911baed727397ec88abc485df971e3cf74d2c0a5f64a646eaee6b3535c45f6 SHA256 checksum (broken-hosts-app-for-splunk_334.tgz) 77083b01de2e009ed3033ed4cadb75d9ec289715977e21c858cc66addc330686 SHA256 checksum (broken-hosts-app-for-splunk_332.tgz) a04c991a6d3315f0a09fbdff8a02ec06cdaccfdc195932204f02cec1e84df041 SHA256 checksum (broken-hosts-app-for-splunk_331.tgz) 2b9889580397288c251de1fcb078443a889a3ef5e8faf73a5bd0546eeaa36ebf SHA256 checksum (broken-hosts-app-for-splunk_320.tgz) f0bbcd26b56e560e477160c874ac19b11dfca9dab68f7c63fd6663464d3546c7 SHA256 checksum (broken-hosts-app-for-splunk_310.tgz) 3c7d3220532f499db16169fe7102e27ed2330fda2aad26a8e157abe91f6a302a
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Broken Hosts App for Splunk

Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
Overview
Details
The Broken Hosts App for Splunk is a useful tool for monitoring data going into Splunk. It has the ability to alert when hosts stop sending data into Splunk, as well as inspect the last time the final combination of data was received by Splunk.

If the arrival of the final log for the index/sourcetype/host combination is later than expected, the Broken Hosts App will send an alert. This allows for quick status detection of the hosts and fast issue resolution.

The Broken Hosts App for Splunk is the app for monitoring missing data in Splunk. The app’s three main objectives include:
1. Alerting when data is missing from Splunk in order to determine the cause.
2. Utilizing saved searches to facilitate rapid detection of the missing data.
3. Creating dashboards for visualization to help with further investigations.

* Latest documentation can be found here:
https://brokenhosts.hurricanelabs.com

Latest documentation can be found here:

Release Notes

Version 4.0.4
Dec. 12, 2018

- updated bh_stats_gen search to fix a bug that might cause false positives
- set eventtypes to be local to the app instead of global

Version 4.0.3
Dec. 10, 2018

- updated AutoSort to allow for arbitrary fields
- update investigation panel to show a timechart of splunk restarts
- fixed type in app.conf that was preventing successful vetting

Version 4.0.2
Nov. 16, 2018

- Fixed a bug with Google Chrome 70+
- Revamped architecture
-- Decouple stats generation from alert generation
-- Eventtype-based aggregations and suppressions
- Additional investigation dashboards
- KV Store auto-sort functionality (enabled by default) to prevent false positive matches

Version 3.3.6
March 19, 2018

v3.3.6
- Row reordering feature added to 'Configure Broken Hosts Lookup' page. Can drag rows using the 'Comments' column.
- 'Add New Suppression' button added to top right to make more visible.
- Ability to Copy formatted row data to clipboard
- Added expectedTime_tmp for backup purposes.
- In edge cases where KV Store is being updated after a row-reorder on Configure page and user refreshes, KV Store data could be lost. For this reason, every change made backs up the current version to a expectedTime_tmp KV Store first
- On initial load of the table it will check if expectedTime is empty, if it is it will then check expectedTime_tmp for data and use that as a backup in case the KV Store was emptied. If both are empty then it is assumed this is a new install and the user has an option to add default values to the KV Store.

Version 3.3.5
Jan. 4, 2018

v3.3.5
- updated the savedsearch to account for sourcetype rewrites

KNOWN ISSUE:
Since kvstore doesn't allow reordering, use this process if a line needs to be moved:
1) go to the broken hosts search and run:
| inputlookup expectedTime | outputlookup expectedTime.csv
(this will populate the CSV with contents of the kvstore)
2) go to the lookup editor app:
- open the expectedTime.csv
- reorder the rows as necessary
- remove _key column
3) go to the splunk search window and run:
| inputlookup expectedTime.csv | outputlookup expectedTime

IMPORTANT: Update Instructions:
- v3.3.3 and greater uses a KV Store instead of a lookup file. Once the app is updated, you will need to populate the KV Store.
- This will only need to be done one time:
1. Run the following search which will dump all the results from the lookup into the KV Store:
| inputlookup expectedTime.csv | outputlookup expectedTime
2. Go to the new "Configure Broken Hosts Lookup" dashboard to check if data is populating on dashboard.

Version 3.3.4
Dec. 13, 2017

v3.3.4
- Removed unnecessary inputs.conf

Version 3.3.2
Aug. 29, 2017

v3.3.2:

- fixed a bug where the the broken hosts dashboard would show the wrong value for "Time Since Last Event"
- updated the app to work if the app directory is renamed
- updated the order of fields in the broken hosts dashboard
- reordered default expectedTime lookup table to be alphabetical
- added "cim_modactions" index to the default suppressions
- added cisco:ios default suppression
- added pan_config and pan:config default suppressions

Version 3.3.1
June 12, 2017

v3.3.1:

- bug fixes for splunk certification
-- scale icon sizes down to splunk approved sizes

v3.3.0:

- updated savedsearch to include any hosts that are sending logs from the future
- added the ability to add custom search additions to make the search more flexible
- added dashboard panel to show suppressed items
- updated dashboard panels to show currently broken items, and all items from the future
- added sparkline to the dashboard panels

Version 3.2.0
Nov. 14, 2016

Modified the savedsearch to use 'tstats' instead of 'metadata' to allow use of sourcetype for tuning.

Updated the savedsearch schedule to run every 30 minutes (because tstats takes longer than metadata).

Updated the savedsearch suppression to suppress for 2 hours instead of 1.

Updated the savedsearch suppression to include sourcetype.

Updated expectedTime lookup table to add a 'sourcetype' column.

Updated first_time script to add 'sourcetype' column to lookup table.

Added Broken Hosts dashboard.

Updated documentation to include Broken Hosts dashboard information.

Added app nav color.

Version 3.1.0
July 29, 2016

RELEASE NOTES:
v3.1:
- Added setup page with default contact and default allowable lateness

v3.0:
- Another major rewrite
- Added the ability to suppress an item
- Added the ability to send different items to different contacts

v2.2:
- fixed issue with the index exclusions in the search
- reversed the order of the release notes, putting new version at the top

v2.1:
- wildcard in lookup table instead of empty quoted string
- app is visible (to allow the "run" button on the saved search to work)
- initial lookup table is now named with .sample extention to not over-write any previous tuning

v2.0: complete re-write of the app from scratch
- uses dbinspect and metadata commands to make this search much faster
- uses a lookup table to make tuning a breeze

352
Installs
2,555
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.