I got a message today saying
"You are low in disk space on partition "D:\splunk\sep\db". Indexing has been paused. Will resume when free disk space rises above 1000MB."
I was hoping if there is a way of creating an email alert for this to make such incidents easier to track so I can get notified if this happens while I'm not logged onto splunk at the time.
Thanks
Hi kavraja,
If you're collecting WMI data you can build a search like this:
sourcetype="WMI:FreeDiskSpace" PercentFreeSpace<10
Otherwise you will need to enable some WMI inputs and read this: Monitor WMI-based data
Once you got this search working, you can easily define an alert out of it.
hope this helps ...
cheers, MuS
If you're on a fairly recent version of Splunk you don't need to collect the data yourself, it's already there in the _introspection
index:
index=_introspection component=Partitions | timechart min(data.free) by data.mount_point
I'm on 6.0 but this index didn't seem to work. Thanks for the help though.
It's been introduced in 6.1.0 😞
Just my luck
Hi kavraja,
If you're collecting WMI data you can build a search like this:
sourcetype="WMI:FreeDiskSpace" PercentFreeSpace<10
Otherwise you will need to enable some WMI inputs and read this: Monitor WMI-based data
Once you got this search working, you can easily define an alert out of it.
hope this helps ...
cheers, MuS
Thanks for the help MuS. Works fine now
Hello Kavraja,
This is kind of easy. Monitor your local server with Splunk and see when it closes to the limit. Run a alert in the same.
Thanks,
L
Thanks for the help linu1988