Monitoring Splunk

Getting "DMC Alert - Near Critical Disk Usage"

schlote
Engager

We are at 91% so not immediately urgent but how do I find out why this is alerting? on one of 2 indexers. Other is at ~80 percent...

We are new to splunk, been running for a few months now. First time this alert came up.

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

It depends on your total disk capacity and your setup.  In order to give some idea;

- Splunk will stop indexing and responding to searches if disk free space gets lower than 5 GB default.

- If your indexes are in those disks you should check your volume settings for indexes.

- Total volumes should be lower than total disk size.

- OS and Datamodels should be taken into account.

You can see below document;

https://docs.splunk.com/Documentation/Splunk/8.1.2/Indexer/Configureindexstoragesize 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

scelikok
SplunkTrust
SplunkTrust

Hi @schlote,

They should be coming from Monitoring Console Platform alerts. The default threshold for Disk Usage is 80. You can check/edit these alerts settings on your Monitoring Console | Settings | Alert Setup page.  

If this reply helps you an upvote and "Accept as Solution" is appreciated.

schlote
Engager

Any suggestions on things to check regarding usage? 

Should I be concerned that this is filling up? or is this normal...

usage is still at 91% today so it has not increased in the last 24h.

 

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...