Getting Data In

forwarder disk space issue


Hi All,

i am using below query to get forwarder disk utilization .. but its not working ..

index=os sourcetype=df | strcat host '@' Filesystem Host_FileSystem | timechart avg(UsePct) by Host_FileSystem

basically our forwarder disk space is getting filled because of  some specific intelligence logs..

here we want to highlight respective team that because of their logs its getting sudden surge logs..




Labels (1)
0 Karma

Revered Legend

What issues are you seeing with result? 

0 Karma



Is your forwarder sending disk space data and are you able to see any data in index=os ? breakdown the search query into individual parts and check 

index=os sourcetype=df
index=os sourcetype=df
| strcat host '@' Filesystem Host_FileSystem



0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...