Getting Data In

forwarder disk space issue

Susha
Engager

Hi All,

i am using below query to get forwarder disk utilization .. but its not working ..

index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com | strcat host '@' Filesystem Host_FileSystem | timechart avg(UsePct) by Host_FileSystem

basically our forwarder disk space is getting filled because of  some specific intelligence logs..

here we want to highlight respective team that because of their logs its getting sudden surge logs..

 

 

 

Labels (1)
0 Karma

somesoni2
SplunkTrust
SplunkTrust

What issues are you seeing with result? 

0 Karma

nmohammed
Contributor

@Susha 

Is your forwarder sending disk space data and are you able to see any data in index=os ? breakdown the search query into individual parts and check 

index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com
index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com
| strcat host '@' Filesystem Host_FileSystem

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...