<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Free disk space in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541724#M10257</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;gcusello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did not find any thing with "TotalSpaceKB" counter. But I found below one. I tried to run&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=perfmon host=XXXXXXXX sourcetype="Perfmon:LogicalDisk" counter="Free Megabytes" instance="C:" OR instance="D:" OR instance="E:" | dedup instance, host &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am getting the events but I am trying to get that in table format with total free space in GB. Currently its showing as MB. Can you help me to conver this into GB. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Time Event&lt;BR /&gt;3/1/21&lt;BR /&gt;3:45:51.000 AM&lt;BR /&gt;03/01/2021 03:45:51.126 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="Free Megabytes"&lt;BR /&gt;instance=E:&lt;BR /&gt;Value=57853&lt;BR /&gt;Collapse&lt;BR /&gt;host = XXXXX source = Perfmon:LogicalDisksourcetype = Perfmon:LogicalDisk&lt;BR /&gt;3/1/21&lt;BR /&gt;3:45:51.000 AM&lt;BR /&gt;03/01/2021 03:45:51.126 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="Free Megabytes"&lt;BR /&gt;instance=D:&lt;BR /&gt;Value=5001&lt;BR /&gt;Collapse&lt;BR /&gt;host = XXXXXXX source = Perfmon:LogicalDisksourcetype = Perfmon:LogicalDisk&lt;BR /&gt;3/1/21&lt;BR /&gt;3:45:51.000 AM&lt;BR /&gt;03/01/2021 03:45:51.126 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="Free Megabytes"&lt;BR /&gt;instance=C:&lt;BR /&gt;Value=57853&lt;BR /&gt;host = XXXXXX source = Perfmon:LogicalDisksourcetype = Perfmon:LogicalDisk&lt;/P&gt;</description>
    <pubDate>Mon, 01 Mar 2021 09:53:57 GMT</pubDate>
    <dc:creator>ravir_jbp</dc:creator>
    <dc:date>2021-03-01T09:53:57Z</dc:date>
    <item>
      <title>Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541353#M10245</link>
      <description>&lt;P&gt;I am trying to get the free space in % for C,D and E drive. I have below events in splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;02/25/2021 08:22:32.272 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="% Free Space"&lt;BR /&gt;instance=E:&lt;BR /&gt;Value=4284.377358490566&lt;/P&gt;&lt;P&gt;02/25/2021 08:20:32.264 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="% Free Space"&lt;BR /&gt;instance=D:&lt;BR /&gt;Value=98.32841691248771&lt;/P&gt;&lt;P&gt;02/25/2021 08:26:32.298 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="% Free Space"&lt;BR /&gt;instance=C:&lt;BR /&gt;Value=43.12314853999153&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for the data like&lt;/P&gt;&lt;P&gt;server name&amp;nbsp; Drive&amp;nbsp; &amp;nbsp;Free space available&lt;/P&gt;&lt;P&gt;xyz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; C:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 20%&lt;/P&gt;&lt;P&gt;xyz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;30%&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 14:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541353#M10245</guid>
      <dc:creator>ravir_jbp</dc:creator>
      <dc:date>2021-02-25T14:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541357#M10246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229744"&gt;@ravir_jbp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you should have also another info about your disks: the total space "TotalSpaceKB",&lt;/P&gt;&lt;P&gt;In this way you can calculate the percentage of free space.&lt;/P&gt;&lt;P&gt;I used the following search in a dashboard:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=windows sourcetype=WinHostMon DriveType=fixed
| stats latest(TotalSpaceKB) AS TotalSpaceKB latest(FreeSpaceKB) AS FreeSpaceKB by host 
| eval 
     Perc=(FreeSpaceKB/TotalSpaceKB)*100,
     TotalSpaceGB=TotalSpaceKB/1024/1024, 
     FreeSpaceGB=FreeSpaceKB/1024/1024 
| sort host 
| table hostTotalSpaceGB FreeSpaceGB Perc 
| rename host AS "Server Name" Name AS "Drive" Perc AS "FreeSpace%"&lt;/LI-CODE&gt;&lt;P&gt;that you could adapt to your needs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 15:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541357#M10246</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-25T15:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541412#M10247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229744"&gt;@ravir_jbp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Your first sample event seems wrong, I assume it is typo. &amp;nbsp;But please try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=windows collection=LogicalDisk object=LogicalDisk
| stats latest(Value) as value by host instance
| eval value=round(value,0).%
| rename instance as Drive, host as "Server Name", value as "Free space available"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:52:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541412#M10247</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-25T19:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541720#M10256</link>
      <description>&lt;P&gt;Hi scelikok,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting below error while execting the script:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Error in 'eval' command: The expression is malformed. An unexpected character is reached at '%'. The search job has failed due to an error. You may be able view the job in the Job Inspector."&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 09:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541720#M10256</guid>
      <dc:creator>ravir_jbp</dc:creator>
      <dc:date>2021-03-01T09:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541724#M10257</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;gcusello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did not find any thing with "TotalSpaceKB" counter. But I found below one. I tried to run&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=perfmon host=XXXXXXXX sourcetype="Perfmon:LogicalDisk" counter="Free Megabytes" instance="C:" OR instance="D:" OR instance="E:" | dedup instance, host &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am getting the events but I am trying to get that in table format with total free space in GB. Currently its showing as MB. Can you help me to conver this into GB. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Time Event&lt;BR /&gt;3/1/21&lt;BR /&gt;3:45:51.000 AM&lt;BR /&gt;03/01/2021 03:45:51.126 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="Free Megabytes"&lt;BR /&gt;instance=E:&lt;BR /&gt;Value=57853&lt;BR /&gt;Collapse&lt;BR /&gt;host = XXXXX source = Perfmon:LogicalDisksourcetype = Perfmon:LogicalDisk&lt;BR /&gt;3/1/21&lt;BR /&gt;3:45:51.000 AM&lt;BR /&gt;03/01/2021 03:45:51.126 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="Free Megabytes"&lt;BR /&gt;instance=D:&lt;BR /&gt;Value=5001&lt;BR /&gt;Collapse&lt;BR /&gt;host = XXXXXXX source = Perfmon:LogicalDisksourcetype = Perfmon:LogicalDisk&lt;BR /&gt;3/1/21&lt;BR /&gt;3:45:51.000 AM&lt;BR /&gt;03/01/2021 03:45:51.126 -0600&lt;BR /&gt;collection=LogicalDisk&lt;BR /&gt;object=LogicalDisk&lt;BR /&gt;counter="Free Megabytes"&lt;BR /&gt;instance=C:&lt;BR /&gt;Value=57853&lt;BR /&gt;host = XXXXXX source = Perfmon:LogicalDisksourcetype = Perfmon:LogicalDisk&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 09:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541724#M10257</guid>
      <dc:creator>ravir_jbp</dc:creator>
      <dc:date>2021-03-01T09:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541728#M10258</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229744"&gt;@ravir_jbp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to convert the value from MB to GB, you have to use the eval command:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval FreeGigabytes=Value/1024&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 10:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541728#M10258</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-01T10:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541742#M10260</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; 

Hi gcusello,

 

THank you for prompt response. That worked for me. I have antoher doubt and I was trying to get the C: D and E drive value into table but I am getting blank results. 

index=perfmon host=XXXXXX sourcetype="Perfmon:LogicalDisk" counter="% Free Space" instance="C:" OR instance="D:" OR instance="E:" | dedup counter | table host counter C:  E:| stats values(host), values(counter), values(C:), values(D:), values(E:)

 

Results I am getting here: I need to get the Value there in C D E

 


20 Per Page
Format
Preview
host	Space	                   C:	  D:	                 E:
XXXXXXX	Free Megabytes	 	 	 
XXXXXXX	% Free Space	 	 	 
&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 11:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541742#M10260</guid>
      <dc:creator>ravir_jbp</dc:creator>
      <dc:date>2021-03-01T11:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541914#M10273</link>
      <description>Hi, can you please help me with this solution as well. thank you</description>
      <pubDate>Tue, 02 Mar 2021 08:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/541914#M10273</guid>
      <dc:creator>ravir_jbp</dc:creator>
      <dc:date>2021-03-02T08:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Free disk space</title>
      <link>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/542237#M10284</link>
      <description>&lt;P&gt;Sorry about I have forgotten quotes, please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=windows collection=LogicalDisk object=LogicalDisk
| stats latest(Value) as value by host instance
| eval value=round(value,0)."%"
| rename instance as Drive, host as "Server Name", value as "Free space available"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 03 Mar 2021 18:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Free-disk-space/m-p/542237#M10284</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-03-03T18:59:31Z</dc:date>
    </item>
  </channel>
</rss>

