Monitoring Splunk

IOPS reported by bonnie++ and Splunk Monitoring console

koshyk
Super Champion

One of our client have 10K HDD in RAID10 and as per Bonnie++ Random Seeks (IOPS) comes to approx 1500 IOPS and wanted to build a dashboard for IOPS and disk usage. I was thinking to re-use the Monitoring console searches

But when I look into the Monitoring Console or DMC, the results show some Indexers of 6000 IOPS !! which is Not possible. Is this a problem with the Splunk api or does this involve RAM assistance?

the query used in DMC is:

| rest splunk_server_group=* splunk_server_group="*" /services/server/status/resource-usage/iostats   | eval iops = round(reads_ps + writes_ps)
0 Karma

nnmiller
SplunkTrust
SplunkTrust

You can't sum these as you have in your query, since they are IOPS per disk. From the /services/server/status/resource-usage/iostats docs page:

Access the most recent disk I/O statistics for each disk. This endpoint is currently supported for Linux, Windows, and Solaris. By default this endpoint is updated every 60s seconds.

Running:

splunk cmd splunkd instrument-resource-usage --debug > some_log_file.log 2>&1

shows that these stats come from /proc/diskstats

(HT: blachance_splunk)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...