<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disk usage Alerts in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13808#M1380</link>
    <description>&lt;P&gt;You should look at the formatting tools in the input box toolbar. There is a button to format code so that it displays as typed in the box.&lt;/P&gt;</description>
    <pubDate>Wed, 19 May 2010 18:58:45 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2010-05-19T18:58:45Z</dc:date>
    <item>
      <title>Disk usage Alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13806#M1378</link>
      <description>&lt;P&gt;I am trying to set up a search then alert on our *nix systems SAN-LUNs storage system. 
I modified a default *NIX disk usage search, however it only works with reporting on  /dev/sda usage. I do not know how to specify the variables for a SAN storage LUN or BOOT partition. &lt;/P&gt;

&lt;P&gt;I have enclosed a copy of my FSTAB file, and a df listing. (Sorry about the formatting?) &lt;/P&gt;

&lt;P&gt;FSTAB 
/dev/VolGroup00/LogVol00 /                       ext3    defaults        1 1
LABEL=/boot             /boot                   ext3    defaults        1 2
tmpfs                   /dev/shm                tmpfs   defaults        0 0
devpts                  /dev/pts                devpts  gid=5,mode=620  0 0
sysfs                   /sys                    sysfs   defaults        0 0
proc                    /proc                   proc    defaults        0 0
/dev/VolGroup00/LogVol01 swap                    swap    defaults        0 0&lt;/P&gt;

&lt;P&gt;root@ihswp1 adminmm0]# df -h -T
Filesystem    Type    Size  Used Avail Use% Mounted on&lt;/P&gt;

&lt;P&gt;/dev/mapper/VolGroup00-LogVol00
              ext3    9.7G  8.6G  602M  94% /
/dev/sda1     ext3     99M   24M   71M  26% /boot
tmpfs        tmpfs   1014M     0 1014M   0% /dev/shm&lt;/P&gt;

&lt;P&gt;Any help would be appreciated. 
Thank you&lt;/P&gt;

&lt;P&gt;V&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 10:24:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13806#M1378</guid>
      <dc:creator>Voltaire</dc:creator>
      <dc:date>2010-05-19T10:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disk usage Alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13807#M1379</link>
      <description>&lt;P&gt;You should look at the Splunk for Unix app, in particular the &lt;CODE&gt;df.sh&lt;/CODE&gt; script for collecting information about your disks in a convenient format for Splunk to parse.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 18:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13807#M1379</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-19T18:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Disk usage Alerts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13808#M1380</link>
      <description>&lt;P&gt;You should look at the formatting tools in the input box toolbar. There is a button to format code so that it displays as typed in the box.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 18:58:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Disk-usage-Alerts/m-p/13808#M1380</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-19T18:58:45Z</dc:date>
    </item>
  </channel>
</rss>

