<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What are the best practice searches for server &amp; OS monitoring? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381926#M6343</link>
    <description>&lt;P&gt;I'd like to implement some basic searches for server and OS monitoring without getting caught up in the differences between sourcetypes and field names.&lt;/P&gt;

&lt;P&gt;I already implemented the &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;Splunk Add-on for Microsoft Windows &lt;/A&gt;and the &lt;A href="https://splunkbase.splunk.com/app/833/"&gt;Splunk Add-on Unix and Linux&lt;/A&gt; but I find that enumerating each sourcetype and coalescing the common fields is feeling unnecessarily complicated.&lt;/P&gt;

&lt;P&gt;Are there any basic searches that provide server and OS monitoring without me having to deal with the complexities of the sourcetype differences? Something akin to the &lt;A href="https://docs.splunk.com/Documentation/CIM/latest/User/Performance"&gt;Performance Model&lt;/A&gt; of the &lt;A href="https://docs.splunk.com/Documentation/CIM/latest/User"&gt;Common Information Model&lt;/A&gt;, perhaps?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Feb 2019 18:07:28 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2019-02-13T18:07:28Z</dc:date>
    <item>
      <title>What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381926#M6343</link>
      <description>&lt;P&gt;I'd like to implement some basic searches for server and OS monitoring without getting caught up in the differences between sourcetypes and field names.&lt;/P&gt;

&lt;P&gt;I already implemented the &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;Splunk Add-on for Microsoft Windows &lt;/A&gt;and the &lt;A href="https://splunkbase.splunk.com/app/833/"&gt;Splunk Add-on Unix and Linux&lt;/A&gt; but I find that enumerating each sourcetype and coalescing the common fields is feeling unnecessarily complicated.&lt;/P&gt;

&lt;P&gt;Are there any basic searches that provide server and OS monitoring without me having to deal with the complexities of the sourcetype differences? Something akin to the &lt;A href="https://docs.splunk.com/Documentation/CIM/latest/User/Performance"&gt;Performance Model&lt;/A&gt; of the &lt;A href="https://docs.splunk.com/Documentation/CIM/latest/User"&gt;Common Information Model&lt;/A&gt;, perhaps?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 18:07:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381926#M6343</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-02-13T18:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381927#M6344</link>
      <description>&lt;P&gt;The answer for this question has been distributed to the following posts:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/797319"&gt;Example of how to measure server disk usage?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/797322"&gt;Example of how to measure server memory usage by host?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/797324"&gt;Example of how to measure server network usage?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://answers.splunk.com/answers/797317/example-of-how-to-measure-server-cpu-usage.html"&gt;Example of how to measure server CPU usage?&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 13 Feb 2019 18:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381927#M6344</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-02-13T18:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381928#M6345</link>
      <description>&lt;P&gt;Added a section about Alerts and incoming link &lt;A href="https://answers.splunk.com/answers/770200/what-are-the-best-event-data-inputs-for-basic-serv.html"&gt;What are the best event-data inputs for basic server and os monitoring?&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 16:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381928#M6345</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-09-04T16:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381929#M6346</link>
      <description>&lt;P&gt;Does the existence of the &lt;A href="https://splunkbase.splunk.com/app/3975/"&gt;Splunk App for Infrastructure&lt;/A&gt; change any of your recommendations?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 23:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381929#M6346</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2019-09-04T23:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381930#M6347</link>
      <description>&lt;P&gt;@gjanders - You're spot on. That's the intent of the "Future" section here. We'll eventually update this for the metrics and &lt;A href="https://splunkbase.splunk.com/app/3975"&gt;Splunk App for Infrastructure&lt;/A&gt; which is quickly becoming a game changer in this domain.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 21:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381930#M6347</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-09-05T21:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381931#M6348</link>
      <description>&lt;P&gt;Updated "Storage Free" search to display by different mount/disks.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 19:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381931#M6348</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-11-13T19:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practice searches for server &amp; OS monitoring?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381932#M6349</link>
      <description>&lt;P&gt;Replaced the answer with its new homes.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 19:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-best-practice-searches-for-server-OS-monitoring/m-p/381932#M6349</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2020-01-29T19:58:07Z</dc:date>
    </item>
  </channel>
</rss>

