Splunk Search

Determine if disk or volume is mounted

james_sro
New Member

I was wondering how can I use Splunk to monitor and notify me if a disk or volume that should be mounted is not mounted. We are looking to implement this within a Linux environment.

Any assistance would be appreciated

0 Karma

MuS
Legend

Hi james_sro,

One way could include the use of a lookup table containing all possible mount points and the use of this app https://splunkbase.splunk.com/app/1553/ to compare against.

It could also be done with some script that runs some df and cat /etc/fstab and prints out the difference into a log which is monitored by Splunk.
You see, there are multiple options to achieve the goal.

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...