<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66857#M16681</link>
    <description>&lt;P&gt;Will the Unix application work on a universal forwarder?  The objective is to have Splunk perform a few simple remote queries.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2012 19:15:20 GMT</pubDate>
    <dc:creator>DTERM</dc:creator>
    <dc:date>2012-02-07T19:15:20Z</dc:date>
    <item>
      <title>splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66855#M16679</link>
      <description>&lt;P&gt;I found the following Splunk query that tells the local disk space.  Is there a similar command that I could use to query stats like diskspace from another host.  (I know how to do this through SSH, however I need the splunk'd solution.)  Thanks!&lt;/P&gt;

&lt;P&gt;[root@splunk bin]# ./splunk search "sourcetype=df | multikv | dedup host,Filesystem | rex field=UsePct \"(?&lt;USAGE&gt;\d+)\"" admin:changeme&lt;/USAGE&gt;&lt;/P&gt;

&lt;P&gt;/dev/sda3          ext4               46G        6.1G         37G         15%    /&lt;/P&gt;

&lt;P&gt;/dev/sda1          ext4              248M         47M        189M         20%    /boot&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2012 18:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66855#M16679</guid>
      <dc:creator>DTERM</dc:creator>
      <dc:date>2012-02-07T18:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66856#M16680</link>
      <description>&lt;P&gt;You could put a forwarder on said 'remote' server, install the *NIX app on it and have it feed your indexer File System usage information via the sourcetype 'df'...&lt;/P&gt;

&lt;P&gt;Then, you could see all of your servers at the same time...just sayin...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2012 19:09:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66856#M16680</guid>
      <dc:creator>Lamar</dc:creator>
      <dc:date>2012-02-07T19:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66857#M16681</link>
      <description>&lt;P&gt;Will the Unix application work on a universal forwarder?  The objective is to have Splunk perform a few simple remote queries.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2012 19:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66857#M16681</guid>
      <dc:creator>DTERM</dc:creator>
      <dc:date>2012-02-07T19:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66858#M16682</link>
      <description>&lt;P&gt;Indeed.&lt;/P&gt;

&lt;P&gt;Please take a look at this thread for possible pitfalls:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/13202/splunk-42-universal-forwarder-nix-app-install-via-cli"&gt;http://splunk-base.splunk.com/answers/13202/splunk-42-universal-forwarder-nix-app-install-via-cli&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2012 19:28:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66858#M16682</guid>
      <dc:creator>Lamar</dc:creator>
      <dc:date>2012-02-07T19:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: splunk query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66859#M16683</link>
      <description>&lt;P&gt;Perfect!!  Thanks so much!!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2012 14:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-query/m-p/66859#M16683</guid>
      <dc:creator>DTERM</dc:creator>
      <dc:date>2012-02-08T14:02:16Z</dc:date>
    </item>
  </channel>
</rss>

