<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/576686#M200978</link>
    <description>&lt;P&gt;I try to use this dashboard but get this error:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Error on line 52:&amp;nbsp;Unexpected close tag&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;after remote this line get another error:&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Error on line -1: Rows can only contain visualization elements or panels, not both.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;any idea?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 30 Nov 2021 06:07:17 GMT</pubDate>
    <dc:creator>indeed_2000</dc:creator>
    <dc:date>2021-11-30T06:07:17Z</dc:date>
    <item>
      <title>Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540524#M152926</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running Splunk Enterprise v7.0.1 (Indexer) on a separate Linux server with Splunk Forwarders on two more Linux servers that are forwarding data to the Indexer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to monitor;&lt;/P&gt;&lt;P&gt;1)CPU Usage,&lt;/P&gt;&lt;P&gt;2)RAM Usage&lt;/P&gt;&lt;P&gt;3)Hard Disk Utilization&lt;/P&gt;&lt;P&gt;4)Load Average&lt;/P&gt;&lt;P&gt;5)Largest Files&lt;/P&gt;&lt;P&gt;6)LAN Card Traffic&lt;/P&gt;&lt;P&gt;The monitoring Console on the Indexer fails to show these metrics for all other instances bar its local.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to monitor these metrics for the forwarders as well as the localhost?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate whoever is willing to help.&lt;/P&gt;&lt;P&gt;Thanks and regards.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 13:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540524#M152926</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-19T13:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540529#M152929</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to do this you should take the logs from the Forwarders using the Splunk Add-on for Unix and Linux (&lt;A href="https://splunkbase.splunk.com/app/833/)" target="_blank"&gt;https://splunkbase.splunk.com/app/833/)&lt;/A&gt;&amp;nbsp;that already has all the inputs to&amp;nbsp;measure the parameters you want.&lt;/P&gt;&lt;P&gt;Then you can create your own dashboards using the logs from the above Add-on or install the Splunk App for Linux and Unix (&lt;A href="https://splunkbase.splunk.com/app/273/" target="_blank"&gt;https://splunkbase.splunk.com/app/273/&lt;/A&gt;) that contains all the dashboard you need.&lt;/P&gt;&lt;P&gt;The third solution is to analyze the above App taking only the searches you need for your Use Cases, eventually customizing them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 13:35:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540529#M152929</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-19T13:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540788#M153050</link>
      <description>&lt;P&gt;Hi Guiseppe,&lt;/P&gt;&lt;P&gt;I have already installed the Add-on for Unix and Linux and that's where I am able to produce a working environment. However, what I don't know is how to measure the parameters that you're suggesting already exist in the add-on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly help me with an elaborated response on that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your kind help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hisham&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 08:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540788#M153050</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-22T08:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540794#M153052</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is a dashboard that i used for Linux Servers monitoring:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Hardware and Software Details: Linux Servers&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="dropdown" token="host"&amp;gt;
      &amp;lt;label&amp;gt;Server&amp;lt;/label&amp;gt;
      &amp;lt;prefix&amp;gt;host="&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;"&amp;lt;/suffix&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;host&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;host&amp;lt;/fieldForValue&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query&amp;gt;
          index=os sourcetype=hardware 
          | eval host=upper(host) 
          | dedup host 
          | sort host 
          | table host
        &amp;lt;/query&amp;gt;
      &amp;lt;/search&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;HostName&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
            index=os sourcetype=hardware $host$ 
            | eval host=upper(host)
            | dedup host 
            | table host
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Description&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
            index=os sourcetype=hardware $host$
            | eval host=upper(host)
            | lookup Perimeter.csv Hostname AS host OUTPUT Description 
            | table Description
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Hardware&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
            index=os sourcetype=hardware $host$
            | dedup host 
            | eval MEMORY_REAL=MEMORY_REAL/1024/1024, MEMORY_SWAP=MEMORY_SWAP/1024/1024, host=upper(host)
            | table CPU_TYPE CPU_COUNT CPU_CACHE MEMORY_REAL MEMORY_SWAP fd0 hdc sda 
            | rename CPU_TYPE AS CPU CPU_COUNT AS "Number of CPUs" CPU_CACHE AS Cache MEMORY_REAL As RAM MEMORY_SWAP AS Swap HARD_DRIVES AS "Hard Disks" fd0 AS "Floppy Disk" hdc AS "Hard Disk" sda AS "Virtual disk"
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;100&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Operative System&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
            index=os sourcetype=Unix:Version $host$
            | table os_name os_release os_version machine_architecture_name
            | rename os_name AS "Operative System" os_release AS Release os_version AS Version machine_architecture_name AS Architecture
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;100&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;df&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;
            index=os  sourcetype=df $host$ 
            | dedup host 
            | multikv 
            | table Filesystem Type Size Used Avail UsePct MountedOn
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;100&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Processes&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=ps $host$ 
            | multikv 
            | table USER PID PSR pctCPU CPUTIME pctMEM RSZ_KB VSZ_KB TTY S ELAPSED COMMAND ARGS&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;netstat&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=netstat $host$ 
            | dedup host 
            | multikv 
            | table Proto Recv-Q Send-Q LocalAddress ForeignAddress State&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;packages&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=package $host$ 
            | multikv 
            | dedup host NAME 
            | table NAME VERSION RELEASE ARCH VENDOR GROUP 
            | sort NAME&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;top command&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=top $host$ 
            | dedup host 
            | multikv 
            | table PID USER PR NI VIRT RES SHR S pctCPU pctMEM cpuTIME COMMAND&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;protocol&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=protocol $host$ 
            | dedup host 
            | multikv 
            | table IPdropped TCPrexmits TCPreorder TCPpktRecv TCPpktSent UDPpktLost UDPunkPort UDPpktRecv UDPpktSent&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;openPorts&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=openPorts $host$ 
            | dedup host 
            | multikv 
            | table Proto Port&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Users with private logins&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=os sourcetype=usersWithLoginPrivs $host$ 
            | dedup host 
            | multikv 
            | table USERNAME HOME_DIR USER_INFO&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;100&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;format type="number" field="Floppy Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Hard Disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Virtual disk"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="RAM"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Swap"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;GB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
        &amp;lt;format type="number" field="Cache"&amp;gt;
          &amp;lt;option name="unit"&amp;gt;kB&amp;lt;/option&amp;gt;
        &amp;lt;/format&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;That you can use to find your searches.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 09:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540794#M153052</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-22T09:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540811#M153061</link>
      <description>&lt;P&gt;Hi Guiseppe,&lt;/P&gt;&lt;P&gt;I tried copy-pasting the entire message that you had just sent (with necessary changes made) but it doesn't fetch me any results. The error says, invalid argument 'index=os'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the botheration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 10:54:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540811#M153061</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-22T10:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540813#M153063</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I stored my linux events in an index called "os", where do you store your Linux events?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 10:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540813#M153063</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-22T10:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540822#M153065</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-02-22 at 4.08.34 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13005i3F6CD8D364EFB1D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-02-22 at 4.08.34 PM.png" alt="Screenshot 2021-02-22 at 4.08.34 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hi Guiseppe,&lt;/P&gt;&lt;P&gt;I've encircled my indexes which stores my Linux events. Had to cancel out some client details, hope you don't mind.&lt;/P&gt;&lt;P&gt;I hope it gives you an idea of how should I be optimizing my search.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 11:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540822#M153065</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-22T11:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540823#M153066</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't like to have events in main index so I hint to modify your input to send all Linux events to os index, anyway, you have two choices:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;replace every &lt;EM&gt;index=os&lt;/EM&gt; in the dashboard with &lt;STRONG&gt;index=os OR index=main&lt;/STRONG&gt;,&lt;/LI&gt;&lt;LI&gt;create an eventtype (called e.g. "&lt;STRONG&gt;linux&lt;/STRONG&gt;") containing the search &lt;STRONG&gt;index=os OR index=main&lt;/STRONG&gt;&amp;nbsp;and then replace every &lt;EM&gt;index=os&lt;/EM&gt;&amp;nbsp;in the dashboard with &lt;STRONG&gt;eventtype=linux&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I always prefer the second, even if it requires more effort.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 11:35:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540823#M153066</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-22T11:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540825#M153067</link>
      <description>&lt;P&gt;Hi Guiseppe,&lt;/P&gt;&lt;P&gt;I received these files as it is otherwise I would've never let indexing into my main.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyhow, according to your advice, I should copy the&amp;nbsp;&lt;SPAN&gt;dashboard that you used for Linux Servers monitoring and replace&lt;STRONG&gt; index=os&lt;/STRONG&gt; with an eventtype called &lt;STRONG&gt;Linux&lt;/STRONG&gt; that searches &lt;STRONG&gt;index=os AND index=main,&lt;/STRONG&gt; right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 12:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540825#M153067</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-22T12:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540849#M153073</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes exactly: in general I hint to follow always this approach in dashboards, the are more flexible.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 15:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540849#M153073</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-22T15:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540970#M153120</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering, can we make use of the Splunk Stream App for monitoring UDP and TCP traffic instead of using&lt;STRONG&gt; sourcetype=protocol&amp;nbsp;&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;If so, I'd very much like to know how is that more beneficial than just the use of sourcetype for monitoring protcols.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hisham&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 08:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540970#M153120</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-23T08:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540972#M153122</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is a different argument and I'm not an expert on Splunk Stream App, so, please, open a a new question about this!&lt;/P&gt;&lt;P&gt;Anyway Splunk Stream App&amp;nbsp;&lt;SPAN&gt;is part of the purpose-built wire data collection and analytics solution from Splunk along with Splunk Add-on for Stream Forwarders for data collection and Splunk Add-on for Stream Wire Data for data parsing and formatting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In few words it permits to perform Packet Capture and monitor traffic for security.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 08:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/540972#M153122</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-23T08:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU Usage, RAM  Usage, Hard Disk Utilization, Load Average, Largest Files and LAN Card Traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/576686#M200978</link>
      <description>&lt;P&gt;I try to use this dashboard but get this error:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Error on line 52:&amp;nbsp;Unexpected close tag&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;after remote this line get another error:&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;Error on line -1: Rows can only contain visualization elements or panels, not both.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;any idea?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 30 Nov 2021 06:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitor-CPU-Usage-RAM-Usage-Hard-Disk-Utilization-Load-Average/m-p/576686#M200978</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-30T06:07:17Z</dc:date>
    </item>
  </channel>
</rss>

