Hi All,
I am trying to setup disk space alert for few servers but I am not getting any results with sourcetype="df".
As I am very new splunk user, could you please let me know is there any other source type available for disk space or how can I set up alert on those servers where sourcetype=df not available?
Thanks in advance.
So is it that some servers have sourcetype=df and some do not? Anyway, this should help you get your sourceytpe lists for your hosts.
Try this in like a 60 minute search on one host that is not reporting df and see if one of the others is where disk space is hiding.
index=* host=SOMELINUXHOSTNAME |dedup sourcetype |table sourcetype
OR..to get a list of what sourcetypes are avaliable for all hosts use this. If you know what index df
should be in substitue that for index=*
index=* | stats values(sourcetype) AS sourcetypes values(index) AS indexes by host
The DF source type is provided from the Splunk NIX TA, and has to be enabled in the modular inputs for this app.
This can be found here : https://splunkbase.splunk.com/app/833/
This needs to be installed on all your servers, and enabled. Most likely you will find that the servers that do not have this agent on them do not have the TA installed, or the input is not enabled, or these are NIX hosts..
Thanks Esix
So is it that some servers have sourcetype=df and some do not? Anyway, this should help you get your sourceytpe lists for your hosts.
Try this in like a 60 minute search on one host that is not reporting df and see if one of the others is where disk space is hiding.
index=* host=SOMELINUXHOSTNAME |dedup sourcetype |table sourcetype
OR..to get a list of what sourcetypes are avaliable for all hosts use this. If you know what index df
should be in substitue that for index=*
index=* | stats values(sourcetype) AS sourcetypes values(index) AS indexes by host
Thank You JDuke.
Yes, some server have sourcetype=df and some servers doesn't have. I checked using above search string few servers doesn't have sourcetype=df.
Is there any way to setup disk space alert on servers that doesn't have sourcetype=df.
Esix is correct. If sourcetype=df is not avaliable on certain hosts they are not reporting df back to the index. This will require that the Splunk NIX TA app be deployed to these hosts. This can either be done manually host by host, or if you have a deployment server setup you can simply deploy the Splunk NIX TA app to the hosts that are not reporting disk space properly.
Thank You