All Apps and Add-ons

Splunk for *nix technology add-on intervals

rainhailrob
Path Finder

Has anyone seen an issue increasing the intervals for TA running SUSE? When I increase the intervals, the *nix 4.5 app stops updating the graphs.

Here are the intervals I changed:
vmstat- 300
iostat- 600
ps- 300
top- 300
protocol- 300
lsof- 600
df- 600
cpu- 300
fschange- 600

However CPU Overview, Memory Overview, Disk Overview don't work for last 15 mins or last 60 mins. I don't know if there isn't enough data points for the graph? I edited the CPU overview "CPU consumption by command" graph to 2 hours and the graph works. Anything less than 120 mins (even 90 mins) and the graph does not fill in.

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

For short time ranges, the CPU graphs sometimes don't seem to populate as expected. The main reason is that the views were created in Splunk's Simple XML and sparse points are not connected such as to make the timecharts visible. We have just fixed that issue in preparing for the next release of the app. Setting the intervals as long as you did will almost certainly exacerbate the problem.

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

For short time ranges, the CPU graphs sometimes don't seem to populate as expected. The main reason is that the views were created in Splunk's Simple XML and sparse points are not connected such as to make the timecharts visible. We have just fixed that issue in preparing for the next release of the app. Setting the intervals as long as you did will almost certainly exacerbate the problem.

0 Karma
Get Updates on the Splunk Community!

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...