<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable IOWAIT? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-disable-IOWAIT/m-p/623730#M14566</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242432"&gt;@jcourses&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;right, the iowait check in&amp;nbsp;&lt;SPAN&gt;distributed health reporter is quite aggressive. You can raise the limits by configure health.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We changed iowait to:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[feature:iowait]
display_name = IOWait
indicator:single_cpu__max_perc_last_3m:description = This indicator tracks the IOWait percentage for the single most bottle-necked CPU on the machine running the Splunk Enterprise instance, over the last 3 minute window. By default, this indicator will turn Yellow if the percentage exceeds 5% and Red if it exceeds 10% during this window.
indicator:single_cpu__max_perc_last_3m:red = 20
indicator:single_cpu__max_perc_last_3m:yellow = 10&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;meaning iowait is yellow for 10% io wait, red for 20% io wait in a 3 min period.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;best regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2022 14:44:30 GMT</pubDate>
    <dc:creator>schose</dc:creator>
    <dc:date>2022-12-08T14:44:30Z</dc:date>
    <item>
      <title>How to disable IOWAIT?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-disable-IOWAIT/m-p/623550#M14565</link>
      <description>&lt;P&gt;We've just upgraded to Splunk 9.0.2 and can see IOWAIT is alerting when logging onto the MASTER that the health is red even though CloudWatch is reporting everything is fine and no complaints from the users.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've spoken to SLT and they are happy for this alert to be disabled.&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 15:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-disable-IOWAIT/m-p/623550#M14565</guid>
      <dc:creator>jcourses</dc:creator>
      <dc:date>2022-12-07T15:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable IOWAIT?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-disable-IOWAIT/m-p/623730#M14566</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242432"&gt;@jcourses&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;right, the iowait check in&amp;nbsp;&lt;SPAN&gt;distributed health reporter is quite aggressive. You can raise the limits by configure health.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We changed iowait to:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[feature:iowait]
display_name = IOWait
indicator:single_cpu__max_perc_last_3m:description = This indicator tracks the IOWait percentage for the single most bottle-necked CPU on the machine running the Splunk Enterprise instance, over the last 3 minute window. By default, this indicator will turn Yellow if the percentage exceeds 5% and Red if it exceeds 10% during this window.
indicator:single_cpu__max_perc_last_3m:red = 20
indicator:single_cpu__max_perc_last_3m:yellow = 10&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;meaning iowait is yellow for 10% io wait, red for 20% io wait in a 3 min period.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;best regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 14:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-disable-IOWAIT/m-p/623730#M14566</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2022-12-08T14:44:30Z</dc:date>
    </item>
  </channel>
</rss>

