How to create Alerts for: Data Ingestion exceeding my licensed amount? Disk sizes are exceeding size on indexers?
I addition how to create an alert for users exceeding their disk quotas allowed & their search quotas?
I really appreciate your help on this. Thx in advance
You can check Alerts for Splunk Admin app (https://splunkbase.splunk.com/app/3796/).
It has lots of alerts categorized by indexers, forwarders, search heads etc.
You can schedule the relevant ones to your infrastructure.