Deployment Architecture

Getting server metrics from Splunk Infrastructure Servers

brent_weaver
Builder

We are just beginning to use iTSI and I would like to create some KPI's that are splunk servers, cpu, memory and disk space. This data seems to already be in the splunk internal indices, I just dont know where... Does anyone?

Any help is much appreciated.

Tags (1)
0 Karma

renjith_nair
Legend

@brent_weaver ,

Probably you are looking for

index="_introspection" sourcetype=splunk_resource_usage

By default, it's disabled on a universal forwarder.

Resources to read -
About Splunk Enterprise platform instrumentation
Configure platform instrumentation

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...