Getting Data In

SAI missing mountpoint from collectd

gballanti
Explorer

Hello,

I'm using SAI to get filesystem usage, unfortunately the mountpoint is not populated, or better it is partial.

The following query (KPI in ITSI)

| mstats min(df.free) as "df_free" max(df.used) as "df_used" WHERE `sai_metrics_indexes` by host,mount span=30s | eval host_dev = host . ":" . mount

doesn't work because the dimension "mount" is missing. Changing "mount" with "device" I get result without mountpoint.

Trying to change the collectd.conf (red part)

<Plugin df>
FSType "ext2"
FSType "ext3"
FSType "ext4"
FSType "XFS"
FSType "rootfs"
FSType "overlay"
FSType "hfs"
FSType "apfs"
FSType "zfs"
FSType "ufs"
MountPoint "/^/.+/"
ReportByDevice false
ValuesAbsolute false
ValuesPercentage true
IgnoreSelected false
</Plugin>

I get data only from one mountpoint (/boot) the other ones are still missing. I don't understand because the mount dimension is missing and only partial mountpoints are taken.

Is it my fault ?

I use the latest version of SAI, ITSI 4.4.3 and Splunk 8.0.3

Thanks

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...