Deployment Architecture

Monitor /proc/meminfo in Splunk

skrish91
Path Finder

Hi,

I would like to monitor /proc/meminfo from my linux servers to get data such as virtual memory used and active memory being used. Is it possible to monitor the /proc/meminfo file using Splunk universal forwarder? I tried using the GUI and i dont get any data for the same. Please advise. Thanks.

0 Karma
1 Solution

soskaykakehi
Path Finder

Hi @skrish91

You can use Splunk Add-on for Unix and Linux App.
This Add-on includes hardware.sh (supports meminfo) and easy to use.
https://splunkbase.splunk.com/app/833/

If you need customize or chooze specific fields, you can reuse hardware.sh or make your own shell scripts ( ex: using cat and awk commands and add a timestamp) .
Then, run your script with Script Inputs on the Universal Forwarder.

Monitor Inputs watch the files and open it. It does not fit to watch under /proc folder files.
/proc file is changing and overwrite realtime and there are no timestamp fields.

View solution in original post

0 Karma

soskaykakehi
Path Finder

Hi @skrish91

You can use Splunk Add-on for Unix and Linux App.
This Add-on includes hardware.sh (supports meminfo) and easy to use.
https://splunkbase.splunk.com/app/833/

If you need customize or chooze specific fields, you can reuse hardware.sh or make your own shell scripts ( ex: using cat and awk commands and add a timestamp) .
Then, run your script with Script Inputs on the Universal Forwarder.

Monitor Inputs watch the files and open it. It does not fit to watch under /proc folder files.
/proc file is changing and overwrite realtime and there are no timestamp fields.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...