I am using the following search for representing usage per mount point. How do I make this a Gauge graph and have one per mount point?
host=$host$ sourcetype="df" earliest=-10m
| multikv fields Used Avail MountedOn
| dedup MountedOn
| eval s = "Used,Available"
| makemv delim="," allowempty=t s
| mvexpand s
| eval Size = if(s=="Used",Used,Avail)
| convert memk(Size) as Size
| chart sum(Size) as "Size in Gb" by s
Also using the Splunk App for Unix and Linux what other interesting search searches could I write?
try like this :
host=$host$ sourcetype="df" earliest=-10m
| multikv fields Used Avail MountedOn
| dedup MountedOn
| eval s = "Used,Available"
| makemv delim="," allowempty=t s
| mvexpand s
| eval Size = if(s=="Used",Used,Avail)
| convert memk(Size) as Size
| chart sum(Size) as "Size in Gb" by s|gauge "Size in Gb" 50 100 125 150
this display the "Size in Gb" on a gauge with 4 regions, (0-50, 50-100, 100-125,125-150)
does not work....
It does not give me four different charts..
hi
I do not understand your problem but I think this link will help you
http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Gauge