Splunk Search

How to trigger the DMC Alert - Near Critical Disk Usage alert on the monitoring console?

moizmmz
Path Finder

Hello,

I've been asked to set up an alert for disk space exceeding 80%.
I enabled the DMC Alert - Near Critical Disk Usage alert on the monitoring console and simply changed it to trigger for 40% (my current usage was on 50% . I just wanted to see if the alert triggers).
But the alert didn't trigger!!!

How do I make sure it triggers?

Tags (1)
0 Karma

prakash007
Builder

Make sure to do this---Edit Alert---->TriggerActions--->Add to Triggered Alerts, and then you can check under Activity--->Triggered Alerts if the alert has been triggered or not, if Triggered, you need to check if you have correct details under Trigger Actions(like email..etc)

I would also look in DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

0 Karma

moizmmz
Path Finder

The alert is not triggering and when I try:
DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

The inputs don't even populate in the multiselect.

I dont see nothin 😞

0 Karma

prakash007
Builder

were you able to run the search manually on DMC..??
can you check you DMCapp--->settings--->setup--->did you see all you instances along with DMC..??
You can also run this on internal logs to check the status of your scheduled search..

index=_internal sourcetype=scheduler host="DMChost" 
| stats count by status, savedsearch_name
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...