Splunk Search

How to trigger the DMC Alert - Near Critical Disk Usage alert on the monitoring console?

moizmmz
Path Finder

Hello,

I've been asked to set up an alert for disk space exceeding 80%.
I enabled the DMC Alert - Near Critical Disk Usage alert on the monitoring console and simply changed it to trigger for 40% (my current usage was on 50% . I just wanted to see if the alert triggers).
But the alert didn't trigger!!!

How do I make sure it triggers?

Tags (1)
0 Karma

prakash007
Builder

Make sure to do this---Edit Alert---->TriggerActions--->Add to Triggered Alerts, and then you can check under Activity--->Triggered Alerts if the alert has been triggered or not, if Triggered, you need to check if you have correct details under Trigger Actions(like email..etc)

I would also look in DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

0 Karma

moizmmz
Path Finder

The alert is not triggering and when I try:
DMC under Search--->SchedulerActivity:Instance---->Instance(DMC)--->look for Skipped Scheduled Reports(it will display the reason too)

The inputs don't even populate in the multiselect.

I dont see nothin 😞

0 Karma

prakash007
Builder

were you able to run the search manually on DMC..??
can you check you DMCapp--->settings--->setup--->did you see all you instances along with DMC..??
You can also run this on internal logs to check the status of your scheduled search..

index=_internal sourcetype=scheduler host="DMChost" 
| stats count by status, savedsearch_name
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...