- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How we can accomplish infrastructure monitoring in Splunk to monitor CPU/MEM/Disk ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @vaneet,
which kind of infratructure are you speaking: Windows and Linux server or other?
If you want to monitor resources of Windows and Linux servers, you can use:
- the Windows Add-on for Microsoft Windows (https://splunkbase.splunk.com/app/742/),
- the Linux Add-on for Linux and Unix (https://splunkbase.splunk.com/app/833/)
to take the data.
then to implement the Use Cases (Dashboards, Alerts and Reports), you can use some apps from Splunk base, e.g.:
- Splunk App for Linux and Unix (https://splunkbase.splunk.com/app/273/),
- Splunk App for Windows Infrastructure (https://splunkbase.splunk.com/app/1680/);
Or otherwise you can create your own dashboards using the data ingested with the Add-Ons, eventually starting from some search that you can find in the above apps.
When you have to start something, always before see in Splunkbase!
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Having been a Splunk admin at a large telco for a few years now, I have simplified our monitoring to a few searches on _introspection index. Very fast and lightweight searches that I bundle in my own app and deploy through Splunk Secure Gateway to the Splunk Mobile app and Splunk TV. Keeps our admin team aware of critical measures like cpu, disc, iostats. Also use the cluster master REST API to watch the status of my indexers (e.g. Up, Down, maintenance mode, etc). Works well and has kept me out of trouble several times.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Splunk introduced the Splunk App for Infrastructure (SAI)
https://splunkbase.splunk.com/app/3975/
https://splunkbase.splunk.com/app/4217/
This application utilizes collectd (linux)/WMI(windows) and metrics to monitor CDM, plus a bunch of other components.
https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure
https://docs.splunk.com/Documentation/Splunk/8.1.1/Metrics/GetMetricsInCollectd
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @vaneet,
which kind of infratructure are you speaking: Windows and Linux server or other?
If you want to monitor resources of Windows and Linux servers, you can use:
- the Windows Add-on for Microsoft Windows (https://splunkbase.splunk.com/app/742/),
- the Linux Add-on for Linux and Unix (https://splunkbase.splunk.com/app/833/)
to take the data.
then to implement the Use Cases (Dashboards, Alerts and Reports), you can use some apps from Splunk base, e.g.:
- Splunk App for Linux and Unix (https://splunkbase.splunk.com/app/273/),
- Splunk App for Windows Infrastructure (https://splunkbase.splunk.com/app/1680/);
Or otherwise you can create your own dashboards using the data ingested with the Add-Ons, eventually starting from some search that you can find in the above apps.
When you have to start something, always before see in Splunkbase!
Ciao.
Giuseppe
