All Apps and Add-ons

Setting up alert using timechart

hhh0505
New Member

Im very lost setting up an alert with timechart in the search.

This is my search:

index=os sourcetype=df MountedOn="/var/opt/" | table * | timechart avg(PercentUsedSpace) by MountedOn

I would like to get the percentage of the disk and would like to be able to setup an alert if it goes above 85%.

Thanks 🙂

Tags (2)
0 Karma

micahkemp
Champion

Try changing your search to only return results that meet your alert threshold:

index=os sourcetype=df MountedOn="/var/opt/" | stats latest(PercentUsedSpace) AS latest_pct_used by MountedOn | search latest_pct_used>85

And as shown above, you probably don't care about the average, so much as you care about the last known percent used.

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...