Getting Data In

How to monitor HD free space on servers?

jbleich
Path Finder

Do I have to have the Splunk forwarder loaded on every server, or is there a way to send that info to a syslog server and have Splunk read it from there?

I'm basically wanting to get an alert anytime an HD on any of my servers reaches 10% or less.....

Anybody done this?

Tags (3)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

You could aggregate you syslog feeds to one central server, and then read in syslog to Splunk on that server. However, you would need to configure your own script to monitor disk utilization and write that to syslog. The Splunk UF and TA-nix has a built in script that will run and report back on the disk utilization. That does require the app to be installed on all your boxes though.

0 Karma

jbleich
Path Finder

So i could load the UF on all of my servers and then just set it to report disk utilization to an index i create in splunk? the UF on every box isnt a concern as long as it doesnt require a lotof resources, having it on all boxes could open a pandoras box of stuff I'd like to do from each server so that might be good 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...