Splunk Search

How to trigger the DMC Alert - Near Critical Disk Usage alert on the monitoring console?

moizmmz
Path Finder

Hello,

I've been asked to set up an alert for disk space exceeding 80%.
I enabled the DMC Alert - Near Critical Disk Usage alert on the monitoring console and simply changed it to trigger for 40% (my current usage was on 50% . I just wanted to see if the alert triggers).
But the alert didn't trigger!!!

How do I make sure it triggers?

Tags (1)
0 Karma

prakash007
Builder

Make sure to do this---Edit Alert---->TriggerActions--->Add to Triggered Alerts, and then you can check under Activity--->Triggered Alerts if the alert has been triggered or not, if Triggered, you need to check if you have correct details under Trigger Actions(like email..etc)

I would also look in DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

0 Karma

moizmmz
Path Finder

The alert is not triggering and when I try:
DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

The inputs don't even populate in the multiselect.

I dont see nothin 😞

0 Karma

prakash007
Builder

were you able to run the search manually on DMC..??
can you check you DMCapp--->settings--->setup--->did you see all you instances along with DMC..??
You can also run this on internal logs to check the status of your scheduled search..

index=_internal sourcetype=scheduler host="DMChost" 
| stats count by status, savedsearch_name
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...