Deployment Architecture

Where in a Linux server is the Distributed Management Console monitoring disk space metrics?

sunnyparmar
Communicator

Hi,

I have a Linux server on which Splunk is installed and its system log is automatically showing on Splunk under Settings -> Distributed management console. Some of the logs are coming from /opt/splunk/etc/system/default/inputs.conf, but still there are some logs like disk space which I am not getting from where it would be taken? So any suggestions here?

Thanks in Advance

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

You can see the Disk Usage under Resource usage tab.

Normally resource usage logs are taken from $SPLUNK_HOME/var/log/introspection/resource_usage.log

Also have a look at https://splunkbase.splunk.com/app/273/ if you have a distributed linux system

Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

You can see the Disk Usage under Resource usage tab.

Normally resource usage logs are taken from $SPLUNK_HOME/var/log/introspection/resource_usage.log

Also have a look at https://splunkbase.splunk.com/app/273/ if you have a distributed linux system

Happy Splunking!
Get Updates on the Splunk Community!

REST API Endoint to create correlation search

Hello, Is it possible to create correlation search in splunk ES app using REST API?

Does Splunk SOAR support mTLS

In the context of connecting Splunk Cloud and Phantom. Does Phantom/Splunk SOAR support mTLS?

Should our Deployment Servers have the Search Head server role on them?

all of our stuff is on premcurrently our dedicated Deployment Servers also have the Search Head role on them, ...