MKKoppula / splunkbase

1 stars 0 forks source link

query #2

Open MKKoppula opened 1 year ago

MKKoppula commented 1 year ago

xyz

MKKoppula commented 1 year ago

MKKoppula commented 1 year ago

[Near Critical Index Usage] action.email = 1 action.email.include.results_link = 0 action.email.include.view_link = 0 action.email.inline = 1 action.email.sendresults = 1 action.email.to = action.email.useNSSubject = 1 action.keyindicator.invert = 0 action.makestreams.param.verbose = 0 alert.suppress = 0 alert.track = 0 counttype = number of events cron_schedule = 20 /6 dispatch.earliest_time = -24h dispatch.latest_time = now display.events.fields = ["host","source","sourcetype","Message","MessageID","Category","Severity","device"] display.general.type = statistics display.page.search.mode = fast display.page.search.tab = statistics display.visualizations.charting.chart = area display.visualizations.custom.type = heat-map-viz.heat-map-viz enableSched = 1 quantity = 0 relation = greater than request.ui_dispatch_app = emr_critical_asset_monitoring request.ui_dispatch_view = search search = | rest /services/data/indexes \ | eval indexUsagePerc=(currentDBSizeMB * 100 / maxTotalDataSizeMB ) \ | table title splunk_server currentDBSizeMB maxTotalDataSizeMB indexUsagePerc | where indexUsagePerc > 80