Splunk Search

How to query Server Stats

gherkin
Explorer

Good afternoon

i'm wondering if I may be able to get a bit of help with this one as I'm struggling on trying to achieve what I want.  I would like to query my 3 servers about their hardware status such as how much space is on the HDD etc etc however i'm really struggling to get my head around how to go about achieving this. 

I've seen a few posts on here which refer to making changes to the input.conf file by adding perfmon but firstly i'm not 100% sure on which input.conf i should be doing this on  (i'm presuming the forwarder) if this is at all the case, and secondly i'm not sure where and how this information in gleamed from.  If anyone would be able to point my in the right direction to a resource that is a step by step guide (or there abouts) i would be very grateful.

TIA

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Have you rebooted the UF service after installing and (every) configuration changes?

Have you gotten those internal logs from that UF server or is those application logs only which are missing?

View solution in original post

0 Karma

gherkin
Explorer

Hi @isoutamo 

I'm using windows machines i'm afraid, I'm also using a UniversalForwarder - I've just read that perhaps I need to enable the introspective_generator_addon.  Is that correct?

0 Karma

Roy_9
Motivator

Hello,


Best solution is to install the splunk add on for windows available on splunk base on the windows server where splunk agent is installed.

this package has got all system level and perfmon metric collection inputs 

just enable those, it will be a lot easier for your situation.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You can try this one https://docs.splunk.com/Documentation/AddOns/released/Windows/AbouttheSplunkAdd-onforWindows

Just install it on your windows machines which are running UF. Do configuration via conf-files or install it first on some HF/your test server and then take conf-files there and install then those (without host name) to UFs.

0 Karma

gherkin
Explorer

Good evening @isoutamo 

apologies for the delay in response, i  was pulled away from the office the last couple of days.

So, i believe i've got it installed correctly, utilised the deployment server and edited the inputs.conf file enabling the sections that I want to monitor - checking the servers they seemed to have pulled down the files correctly.

I've also created an index (client_monitoring) and used:

index = client_monitoring

in the inputs.conf file.  However if I try and do a search on that index I get No results found.

If I look at the Index's management page no data appears to be coming in as the Event Count is 0.

Apologies if this is all quite straight forward, I'm trying to teach myself this as I go along lol

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you rebooted the UF service after installing and (every) configuration changes?

Have you gotten those internal logs from that UF server or is those application logs only which are missing?

0 Karma

gherkin
Explorer

good morning @isoutamo so I did restart the UF on one server (i was just testing it at the time to see if it works).

Apologies, i don't fully understand you logs sentence. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Internal logs are UF’s own logs which told how it works. Application logs are e.g. windows, web servers or other logs which are generated by some application.

0 Karma

gherkin
Explorer

Ok cool, gotcha.  So restarted the UF again today just to make sure and everything has kicked in, so either I restarted it to soon last time (ie before the conf file had come down) or it didn't necessarily start correctly.

Thank you once again, onto the my next research topic.....Dashboards 🙂

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if you are using linux then you should use this https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/AbouttheSplunkAdd-onforUnixandLinux and follow that configuration instructions https://docs.splunk.com/Documentation/UnixAddOn/6.0.0/User/Enabledataandscriptedinputs

If you are using HF then you could configure that via GUI otherwise you must use those configuration files.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...