looking to find a procedure or help to configure i/o so i can capture the same from universal forwarders.
currently the iostat source type is not showing any i/o for disk, but it shows only for cpu and mem.
can you guide me to set this up so i can collect disk i/o
thanks
Go to your DS CLI and do this:
find /opt/splunk/etc/deployment-apps -type f -name inputs.conf -exec grep -il iostat {} \;
When you find the app (it could be one of several), make sure that there is a local
directory and in there an inputs.conf
file (if not, create them). Then copy the stanza header from the inputs.conf
in the default
directory (probably [script://./bin/iostat.sh]
) and add disabled = 0
on the next line. Save it and then reload the configurations on DS to let it go out.
Go to your DS CLI and do this:
find /opt/splunk/etc/deployment-apps -type f -name inputs.conf -exec grep -il iostat {} \;
When you find the app (it could be one of several), make sure that there is a local
directory and in there an inputs.conf
file (if not, create them). Then copy the stanza header from the inputs.conf
in the default
directory (probably [script://./bin/iostat.sh]
) and add disabled = 0
on the next line. Save it and then reload the configurations on DS to let it go out.
Maybe it's disabled, like mine ; -)
[script://./bin/iostat.sh]
interval = 60
sourcetype = iostat
source = iostat
index = os
disabled = 1
thanks that did the trick... 🙂