Alerting

Create alert when memory consumption threshold is reached

filipvb
New Member

Can anybody help me in creating an alert when for example only 100MB of memory are available?
Not on a remote server, just on the local Splunk server(4.3) itself. It seemed a simple job at first, but I still didn't succeed, even after a lot of reading 😞

I succeeded in creating a local performance monitoring collection with a counter on "Available MBytes" But that's about it, creating an alert for it fills my alert window. Where can I set a threshold to only alert me if "Available MBytes" drop under e.g. 100?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi filipvb

save your search and have it run as often you like with a schedule. in the scheduled saved search itself you can define an alert condition and what should be done when the condition is hit.

even more reading can be done here

cheers

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...