September 24, 2026
Log Source Monitor
Monitor when every index, sourcetype and host last sent data and get alerted when logs stop arriving. Detection uses receive time, so clock or time zone issues don't cause false outages. Includes per-source thresholds, outage history, index inventory and forwarder monitoring. No Python or custom indexes required.Built by Mustafa Gurkan KARAKAYASplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4
Log in to rate this app
Log Source Monitor tracks when every log source last sent data to Splunk and alerts you when data stops arriving. A log source is each unique combination of index, sourcetype and host, so you see exactly which firewall, server or application went silent and for how long. Detection is based on when data was received rather than on event timestamps, so sources with time zone or clock problems do not show up as false outages. You can set different delay and outage thresholds per index, sourcetype or host using wildcard rules. Alerts fire once when an outage starts and once when it recovers, instead of repeating every few minutes. The app also inventories every index with its size, retention and 24-hour activity, and shows forwarders that have disconnected or are connected but not sending data. It runs entirely on the search head, stores its data in the KV Store, and needs no Python, scripted inputs or custom indexes.
Log in to report this app listing.