Splunk Enterprise

using mcollect on contionous basis

Silah
Path Finder

Hi Folks

I've been using mcollect to collect metrics from the events in my indexes and I thought if I set up an alert with the mcollect part in the search, it would automatically collect the metrics every X minutes but that doesn't seem to be working, the metrics are only collected when I run the search manually.

 

Any suggestions to how I can make mcollect just automatically collect the metrics I am looking for ?

 

Thanks

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

If this is the only thing modifying your metrics index you could verify whether the data is not mcollected at all or just "mistimed".

Run

| mstats count(*) where index=<your_metrics_index>
| transpose 0
| stats sum("row 1") as total

over all-time before and after the scheduled search runs and verify the counts

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Are you sure the user for which the search is scheduled has appropriate capabilities to run mcollect and access to the destination index?

0 Karma

Silah
Path Finder

I think so. I considered permissions and tried it in a lab setting as the admin user and it was the same result.

 

Besides, it works fine when the same user does it manually so I wouldn't have thought it would be any different for an automated one

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If this is the only thing modifying your metrics index you could verify whether the data is not mcollected at all or just "mistimed".

Run

| mstats count(*) where index=<your_metrics_index>
| transpose 0
| stats sum("row 1") as total

over all-time before and after the scheduled search runs and verify the counts

0 Karma

Silah
Path Finder

I do feel a bit stupid now..

My Cron was wrong. The method was perfectly sane.

I did struggle to find any actual documentation to say that this was a way of doing it, so I hope this question will help future searchers determine that.

Thanks for helping my grey matter along

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...