Splunk Search

How to search for disk usage greater than 70 percent for 10 mins?

londonColney
Loves-to-Learn

I wanted to know how we can construct a search query for a service which is running on a centOS server and the utilization has exceeded 70 per cent for last 10 mins ? We are supposed to create an alert if such kind of situation arises? Any help would be greatly appreciated.

Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you considered Splunk Add-on for Unix and Linux from SplunkBase?

0 Karma

londonColney
Loves-to-Learn

@ITWhisperer No I have not considered it.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...