Hi All,
i am using below query to get forwarder disk utilization .. but its not working ..
index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com | strcat host '@' Filesystem Host_FileSystem | timechart avg(UsePct) by Host_FileSystem
basically our forwarder disk space is getting filled because of some specific intelligence logs..
here we want to highlight respective team that because of their logs its getting sudden surge logs..
What issues are you seeing with result?
Is your forwarder sending disk space data and are you able to see any data in index=os ? breakdown the search query into individual parts and check
index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com
index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com
| strcat host '@' Filesystem Host_FileSystem