Monitoring Splunk

Infrastructure monitoring in Splunk

vaneet
Explorer

How we can accomplish infrastructure monitoring in Splunk to monitor CPU/MEM/Disk ?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @vaneet,

which kind of infratructure are you speaking: Windows and Linux server or other?

If you want to monitor resources of Windows and Linux servers, you can use:

to take the data.

then to implement the Use Cases (Dashboards, Alerts and Reports), you can use some apps from Splunk base, e.g.:

Or otherwise you can create your own dashboards using the data ingested with the Add-Ons, eventually starting from some search that you can find in the above apps.

When you have to start something, always before see in Splunkbase!

Ciao.

Giuseppe

View solution in original post

thormanrd
Path Finder

Having been a Splunk admin at a large telco for a few years now, I have simplified our monitoring to a few searches on _introspection index.  Very fast and lightweight searches that I bundle in my own app and deploy through Splunk Secure Gateway to the Splunk Mobile app and Splunk TV.  Keeps our admin team aware of critical measures like cpu, disc, iostats.  Also use the cluster master REST API to watch the status of my indexers (e.g. Up, Down, maintenance mode, etc).  Works well and has kept me out of trouble several times.  

0 Karma

ekenne06
Path Finder

Splunk introduced the Splunk App for Infrastructure (SAI)

https://splunkbase.splunk.com/app/3975/

https://splunkbase.splunk.com/app/4217/

 

This application utilizes collectd (linux)/WMI(windows) and metrics to monitor CDM, plus a bunch of other components. 

https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure

https://docs.splunk.com/Documentation/Splunk/8.1.1/Metrics/GetMetricsInCollectd

 

 

gcusello
SplunkTrust
SplunkTrust

Hi @vaneet,

which kind of infratructure are you speaking: Windows and Linux server or other?

If you want to monitor resources of Windows and Linux servers, you can use:

to take the data.

then to implement the Use Cases (Dashboards, Alerts and Reports), you can use some apps from Splunk base, e.g.:

Or otherwise you can create your own dashboards using the data ingested with the Add-Ons, eventually starting from some search that you can find in the above apps.

When you have to start something, always before see in Splunkbase!

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...