Splunk Search

How to trigger the DMC Alert - Near Critical Disk Usage alert on the monitoring console?

moizmmz
Path Finder

Hello,

I've been asked to set up an alert for disk space exceeding 80%.
I enabled the DMC Alert - Near Critical Disk Usage alert on the monitoring console and simply changed it to trigger for 40% (my current usage was on 50% . I just wanted to see if the alert triggers).
But the alert didn't trigger!!!

How do I make sure it triggers?

Tags (1)
0 Karma

prakash007
Builder

Make sure to do this---Edit Alert---->TriggerActions--->Add to Triggered Alerts, and then you can check under Activity--->Triggered Alerts if the alert has been triggered or not, if Triggered, you need to check if you have correct details under Trigger Actions(like email..etc)

I would also look in DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

0 Karma

moizmmz
Path Finder

The alert is not triggering and when I try:
DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

The inputs don't even populate in the multiselect.

I dont see nothin 😞

0 Karma

prakash007
Builder

were you able to run the search manually on DMC..??
can you check you DMCapp--->settings--->setup--->did you see all you instances along with DMC..??
You can also run this on internal logs to check the status of your scheduled search..

index=_internal sourcetype=scheduler host="DMChost" 
| stats count by status, savedsearch_name
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...