<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where do I configure the health.conf so that I can disable the IOWaits alert? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/597100#M12485</link>
    <description>&lt;P&gt;Yes, I restarted the MC several times after the changes to the configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I have not edited the health.conf on the Indexers. They are quite difficult to restart at the moment and I was hoping that someone would have a KB or document that could help (or know definitively) before I went there.&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 08:20:06 GMT</pubDate>
    <dc:creator>BlueSocket</dc:creator>
    <dc:date>2022-05-10T08:20:06Z</dc:date>
    <item>
      <title>Where do I configure the health.conf so that I can disable the IOWaits alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596827#M12477</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I have a Search Head, Deployment Server, Monitoring Console, a Cluster Manager, an Indexer Cluster and two unclustered Indexers.&lt;/P&gt;&lt;P&gt;On the Monitoring Console, I get alerts about the IOWaits being high on the two unclustered indexers and this has been happening only since we upgraded to 8.2.5.&lt;/P&gt;&lt;P&gt;There is no evidence of any issues, other than this alert in SplunkWeb and I want to disable it. I am using the following KB article:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Healthconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.5/Admin/Healthconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;On the Monitoring Console server, I have put the following into the etc\apps\search\local\health.conf file:&lt;/P&gt;&lt;P&gt;[feature:iowait]&lt;BR /&gt;alert:sum_top3_cpu_percs__max_last_3m.disabled = 1&lt;/P&gt;&lt;P&gt;However, I am still getting the appearing in SplunkWeb on the&amp;nbsp;Monitoring Console server.&lt;/P&gt;&lt;P&gt;Why is this? Am I configuring the health.conf in the wrong server or the wrong folder, or what? When I run a cmd btool health list, I see the configuration there, but Splunk is not doing as it is being told! If I am doing the wrong thing, even, can someone point me to some documentation that explains what I should be doing?&lt;/P&gt;&lt;P&gt;Thanks in advance!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2022 16:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596827#M12477</guid>
      <dc:creator>BlueSocket</dc:creator>
      <dc:date>2022-05-07T16:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I configure the health.conf so that I can disable the IOWaits alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596829#M12478</link>
      <description>&lt;P&gt;Did you restart the MC server after changing the config file?&lt;/P&gt;&lt;P&gt;Have you tried making the same health.conf change on the indexers?&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2022 17:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596829#M12478</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-05-07T17:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I configure the health.conf so that I can disable the IOWaits alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/597100#M12485</link>
      <description>&lt;P&gt;Yes, I restarted the MC several times after the changes to the configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, I have not edited the health.conf on the Indexers. They are quite difficult to restart at the moment and I was hoping that someone would have a KB or document that could help (or know definitively) before I went there.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 08:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/597100#M12485</guid>
      <dc:creator>BlueSocket</dc:creator>
      <dc:date>2022-05-10T08:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I configure the health.conf so that I can disable the IOWaits alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/612079#M13821</link>
      <description>&lt;P&gt;The Health feature has caused some confusion regards local vs. distributed config. I have investigated this and it is very flexible to configure even though the docs is not so clear about it. So far I have not found any Answers posts that isn't possible to solve using standard config.&lt;/P&gt;&lt;P&gt;If you do configuration locally on Monitoring Console (DMC), as you described, that threshold will only be valid for the DMC local host. There is no distributed threashold. You need to configure the threshold on each and every enterprise instance (e.g. your standalone indexers). Either you do config in Splunk Web under Settings menu on each enterprise instance and just click Save. Or toggle Status Disable/Enable. This will take direct effect and does not require restart.&lt;/P&gt;&lt;P&gt;If you instead configure health.conf on each instance, example&amp;nbsp;disable iowait, put this in health.conf&lt;/P&gt;&lt;PRE&gt;[feature:iowait]&lt;BR /&gt;disabled = 1&lt;/PRE&gt;&lt;P&gt;And then you need to do a reload e.g.&amp;nbsp;&lt;A target="_blank" rel="noopener"&gt;http://&amp;lt;your_splunk&amp;gt;:&amp;lt;splunk_port&amp;gt;/debug/refresh&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a index cluster, applying a cluster bundle, this will trigger a restart of the peers. Version 8.2.4&lt;/P&gt;&lt;P&gt;Hope this solves your issue.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 21:46:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/612079#M13821</guid>
      <dc:creator>pellegrini</dc:creator>
      <dc:date>2022-11-14T21:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Where do I configure the health.conf so that I can disable the IOWaits alert?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/612086#M13822</link>
      <description>&lt;P&gt;In addition you can use these searches to benchmark iowait performance over time, so you can set relevant thresholds for your environment. Just replace the hostname:&lt;/P&gt;&lt;P&gt;CPU IOwait average&lt;/P&gt;&lt;PRE&gt;index=_internal&amp;nbsp; source="*/splunk/var/log/splunk/health.log"&amp;nbsp;&amp;nbsp; &lt;BR /&gt;feature=IOWait component=PeriodicHealthReporter node_type=indicator &lt;BR /&gt;indicator=avg_cpu__max_perc_last_3m host=ind0* &lt;BR /&gt;| timechart span=30s max(measured_value) min(due_to_threshold_value) by host&lt;/PRE&gt;&lt;P&gt;CPU IOwait single CPU&lt;/P&gt;&lt;PRE&gt;index=_internal&amp;nbsp; source="*/splunk/var/log/splunk/health.log"&amp;nbsp;&amp;nbsp; &lt;BR /&gt;feature=IOWait component=PeriodicHealthReporter node_type=indicator &lt;BR /&gt;indicator=single_cpu__max_perc_last_3m host=ind0* &lt;BR /&gt;| timechart span=300s max(measured_value) min(due_to_threshold_value) by host&lt;/PRE&gt;&lt;P&gt;CPU IOwait top3 CPU&lt;/P&gt;&lt;PRE&gt;index=_internal&amp;nbsp; source="*/splunk/var/log/splunk/health.log"&amp;nbsp;&amp;nbsp;&lt;BR /&gt;feature=IOWait component=PeriodicHealthReporter node_type=indicator &lt;BR /&gt;indicator=sum_top3_cpu_percs__max_last_3m host=ind0* &lt;BR /&gt;| timechart span=30s max(measured_value) min(due_to_threshold_value) by host&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 11:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/612086#M13822</guid>
      <dc:creator>pellegrini</dc:creator>
      <dc:date>2022-09-06T11:40:40Z</dc:date>
    </item>
  </channel>
</rss>

