Alerting

"DM sourcetypes too much data" and "DM missing sourcetypes"

AKG
Path Finder

Hi

We are getting following Alert and wondering if you could tell us what does this mean and what can we do so that we are not using up licensing quote.

1) DM sourcetypes too much data
2) DM missing sourcetypes

Thank you in advance

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

It shows you that the alerts you have enabled in Deployment Monitor have triggered.

"DM Sourcetypes too much data" informs you of some sourcetypes that have increased in volume when compared to an earlier point in time. Like, "In the last hour we have received 75% more firewall logs than compared with the hour before that".

Conversely, "DM Missing sourcetypes" informs you of some sourcetypes that are not (currently) being received, but they have been before, like "In the last hour we have not received any WindowsEventLogs, but the hour before that, we did".

I don't remember the exact timeslices used for comparison, or the percentage values used as thresholds on too much/too little data. You should check out the landing page of the Deployment Monitor, where these types of message are listed. This is also the place where you can activate alerting on them. Or you can look at the saved searches directly in Manager or the config files.

Hope this helps,

K

lukejadamec
Super Champion

DM has been my greatest friend for monitoring which app/server/source etc... was threatening or violating my license limits.
You should use DM to monitor your deployment, and if you see a Particular problem, then post a question with the specifics.

0 Karma

AKG
Path Finder

Thanks Guys

0 Karma

lukejadamec
Super Champion

It is not possible for us to tell you why your alerts are being triggered other than to say what Kristian already said. However, Splunk is built to tell you why, you just have to search for it. In DM for the alert in question, click on the links associated with the alert to drill into the search.

0 Karma

lukejadamec
Super Champion

In DM, and other Apps, "Others" means "the other's of this category that are not listed because of space/preferences". To view the complete list you need to "view data" or view the data set below the chart.

0 Karma

AKG
Path Finder

Hi Kristian

Thank you for the reply, yes I have enabled this alert wanted to see how will it work.

Now I know what it does(thanks for the explanation), Now i was wondering if you know how this situation occurs and what we can do to avoid this.

I also notice that there are data coming in listed as a host name "Others" i am guessing this is as you have explained.

Thank you

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...