<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring disk space in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Monitoring-disk-space/m-p/506598#M141729</link>
    <description>&lt;P&gt;When you run the &lt;FONT face="courier new,courier"&gt;rest&lt;/FONT&gt; command by itself, do you see both mount points?&lt;/P&gt;&lt;P&gt;BTW, the &lt;FONT face="courier new,courier"&gt;rename&lt;/FONT&gt; command references the capacity field, but that field was discarded by &lt;FONT face="courier new,courier"&gt;stats&lt;/FONT&gt;.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jun 2020 21:00:02 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-06-29T21:00:02Z</dc:date>
    <item>
      <title>Monitoring disk space</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitoring-disk-space/m-p/506595#M141726</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; I'm using the following search to monitor disk space.&amp;nbsp; I have 2 partitions, drive D and E.&amp;nbsp; I am only returning results for drive D.&amp;nbsp; I would have expected results for both.&amp;nbsp; Any thoughts are appreciated. thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;| rest splunk_server=Splunk01 /services/server/status/partitions-space | eval free = if(isnotnull(available), available, free) | eval usage = round((capacity - free) / 1024, 2) | eval capacity = round(capacity / 1024, 2) | eval compare_usage = usage." / ".capacity | eval pct_usage = round(usage / capacity * 100, 2) | stats first(fs_type) as fs_type first(compare_usage) as compare_usage first(pct_usage) as pct_usage by mount_point | rename mount_point as "Mount Point", fs_type as "File System Type", compare_usage as "Disk Usage (GB)", capacity as "Capacity (GB)", pct_usage as "Disk Usage (%)"&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 20:42:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitoring-disk-space/m-p/506595#M141726</guid>
      <dc:creator>steveo2</dc:creator>
      <dc:date>2020-06-29T20:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring disk space</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Monitoring-disk-space/m-p/506598#M141729</link>
      <description>&lt;P&gt;When you run the &lt;FONT face="courier new,courier"&gt;rest&lt;/FONT&gt; command by itself, do you see both mount points?&lt;/P&gt;&lt;P&gt;BTW, the &lt;FONT face="courier new,courier"&gt;rename&lt;/FONT&gt; command references the capacity field, but that field was discarded by &lt;FONT face="courier new,courier"&gt;stats&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 21:00:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Monitoring-disk-space/m-p/506598#M141729</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-29T21:00:02Z</dc:date>
    </item>
  </channel>
</rss>

