Monitoring Splunk

Critical System Physical Memory Usage

cybermonday
Explorer

Oracle Linux 7.5
Splunk Core 7.2.5

Alert Name -- DMC Alert - Critical System Physical Memory Usage
The alert works on below rest command which pulls 2 fields from systems --- mem and mem_used. 


| rest splunk_server_group=dmc_group_* /services/server/status/resource-usage/hostwide

we have learned that this alert is giving false value after confirming from oracle support. 
as per them, when running "free -m" command - "In Oracle Linux 7/8, the focus should be on the "available" column.
The available column estimates how much memory is available for starting new applications without swapping. If, the system still has 28G available memory and you see 26G  in "used" - that is because this is how Linux behaves. Linux treats the memory that can be made available upon request as "used"." 

also see - -   
https://www.redhat.com/sysadmin/dissecting-free-command


So, I am interested to fetch the "available memory" field from hosts.  So that I can do some eval and then optimize the existing alert to suit fit to our needs. 


Is there any way, how to pull the "available memory" field from hosts?

Labels (1)
Tags (1)
0 Karma

evinasco08
Explorer

Hi @cybermonday could you fix the problem?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...