Monitoring Splunk

How come _introspection reports only about root?

danielbb
Motivator

Introspection seems to give me the data.mount_point only for "/" and not for the other file systems that I can see via the Linux "df -kh" command. How come?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

By default this has configured to look only SPLUNK_HOME mount point. I don’t know if there is way to add additional mount points there. 

If you need monitor other mount points and other Linux statistics, I think that you should use e.g. *nix ta for collecting logs and metrics https://splunkbase.splunk.com/app/833

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in Splunk Cloud Platform ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...