<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with alert running from DMC for memory overrun. in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Issue-with-alert-running-from-DMC-for-memory-overrun/m-p/520160#M4458</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have an alert in place that uses the REST API to determine when a server is using to much memory and then the server is restarted.&amp;nbsp; It had been working great, however last week we had an alert come through that listed every box connected to the DMC.&amp;nbsp; This caused some restarts that created an issue.&amp;nbsp; When trying to look at the stats for the machines at the time of the alert, none of the servers show meeting that condition.&amp;nbsp; Am I doing something wrong here?&lt;/P&gt;
&lt;P&gt;We are using the below search:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| rest splunk_server_group=dmc_group_* /services/server/status/resource-usage/hostwide
| eval percentage=round(mem_used/mem,3)*100
| where percentage &amp;gt; 90
| fields splunk_server, percentage, mem_used, mem
| rename splunk_server AS ServerName, mem AS "Physical memory installed (MB)", percentage AS "Memory used (%)", mem_used AS "Memory used (MB)"
| rex field=ServerName "\s*(?&amp;lt;ServerName&amp;gt;\w+[\d+]).*"
| table ServerName
| sort - ServerName
| stats list(ServerName) as ServerName delim=","
| nomv ServerName&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 25 Sep 2020 20:46:40 GMT</pubDate>
    <dc:creator>mookiie2005</dc:creator>
    <dc:date>2020-09-25T20:46:40Z</dc:date>
    <item>
      <title>Issue with alert running from DMC for memory overrun.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issue-with-alert-running-from-DMC-for-memory-overrun/m-p/520160#M4458</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have an alert in place that uses the REST API to determine when a server is using to much memory and then the server is restarted.&amp;nbsp; It had been working great, however last week we had an alert come through that listed every box connected to the DMC.&amp;nbsp; This caused some restarts that created an issue.&amp;nbsp; When trying to look at the stats for the machines at the time of the alert, none of the servers show meeting that condition.&amp;nbsp; Am I doing something wrong here?&lt;/P&gt;
&lt;P&gt;We are using the below search:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| rest splunk_server_group=dmc_group_* /services/server/status/resource-usage/hostwide
| eval percentage=round(mem_used/mem,3)*100
| where percentage &amp;gt; 90
| fields splunk_server, percentage, mem_used, mem
| rename splunk_server AS ServerName, mem AS "Physical memory installed (MB)", percentage AS "Memory used (%)", mem_used AS "Memory used (MB)"
| rex field=ServerName "\s*(?&amp;lt;ServerName&amp;gt;\w+[\d+]).*"
| table ServerName
| sort - ServerName
| stats list(ServerName) as ServerName delim=","
| nomv ServerName&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 25 Sep 2020 20:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issue-with-alert-running-from-DMC-for-memory-overrun/m-p/520160#M4458</guid>
      <dc:creator>mookiie2005</dc:creator>
      <dc:date>2020-09-25T20:46:40Z</dc:date>
    </item>
  </channel>
</rss>

