Skip to main content
Log Source Monitor app icon

Log Source Monitor

Monitor when every index, sourcetype and host last sent data and get alerted when logs stop arriving. Detection uses receive time, so clock or time zone issues don't cause false outages. Includes per-source thresholds, outage history, index inventory and forwarder monitoring. No Python or custom indexes required.Built by Mustafa Gurkan KARAKAYA
splunk product badge

Default Version 1.1.2

September 24, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

Rating
5
(3)

Log in to rate this app

Support
Developer Supported

Log Source Monitor tracks when every log source last sent data to Splunk and alerts you when data stops arriving. A log source is each unique combination of index, sourcetype and host, so you see exactly which firewall, server or application went silent and for how long. Detection is based on when data was received rather than on event timestamps, so sources with time zone or clock problems do not show up as false outages. You can set different delay and outage thresholds per index, sourcetype or host using wildcard rules. Alerts fire once when an outage starts and once when it recovers, instead of repeating every few minutes. The app also inventories every index with its size, retention and 24-hour activity, and shows forwarders that have disconnected or are connected but not sending data. It runs entirely on the search head, stores its data in the KV Store, and needs no Python, scripted inputs or custom indexes.