Monitoring Splunk

monitor inode useage

Vinesh93
Explorer

Is there any possible solution to monitor the inode usage of linux system in Splunk?

Tags (1)
0 Karma
1 Solution

PavelP
Motivator

you need to install an Add-on for Linux and modify/copy its df.sh script, change

CMD='df -TPh'

to

CMD='df -TPhi'

you can remove -h parameter too.

Output will be:

Filesystem   Type              Size        Used       Avail      UsePct    MountedOn
/dev/sda1   ext4               57G         19G         35G         36%    /

and without -h:

Filesystem    Type              Size        Used       Avail      UsePct    MountedOn
/dev/sda1    ext4           7627488      104349     7523139          2%    /

you can modify the FORMAT and HEADER variables in df.sh further to show Inodes/IUsed/IFree/IUse% instead of Size/Used/Avail/UsePct

View solution in original post

PavelP
Motivator

you need to install an Add-on for Linux and modify/copy its df.sh script, change

CMD='df -TPh'

to

CMD='df -TPhi'

you can remove -h parameter too.

Output will be:

Filesystem   Type              Size        Used       Avail      UsePct    MountedOn
/dev/sda1   ext4               57G         19G         35G         36%    /

and without -h:

Filesystem    Type              Size        Used       Avail      UsePct    MountedOn
/dev/sda1    ext4           7627488      104349     7523139          2%    /

you can modify the FORMAT and HEADER variables in df.sh further to show Inodes/IUsed/IFree/IUse% instead of Size/Used/Avail/UsePct

Vinesh93
Explorer

@PavelP Thanks a lot, that works like a charm!!!

0 Karma

PavelP
Motivator

thank you @Vinesh93 , please accept the answer as solution so everybody can benefit from it

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...