Do I have to have the Splunk forwarder loaded on every server, or is there a way to send that info to a syslog server and have Splunk read it from there?
I'm basically wanting to get an alert anytime an HD on any of my servers reaches 10% or less.....
Anybody done this?
You could aggregate you syslog feeds to one central server, and then read in syslog to Splunk on that server. However, you would need to configure your own script to monitor disk utilization and write that to syslog. The Splunk UF and TA-nix has a built in script that will run and report back on the disk utilization. That does require the app to be installed on all your boxes though.
So i could load the UF on all of my servers and then just set it to report disk utilization to an index i create in splunk? the UF on every box isnt a concern as long as it doesnt require a lotof resources, having it on all boxes could open a pandoras box of stuff I'd like to do from each server so that might be good 🙂