Getting Data In

forwarder disk space issue

Susha
Engager

Hi All,

i am using below query to get forwarder disk utilization .. but its not working ..

index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com | strcat host '@' Filesystem Host_FileSystem | timechart avg(UsePct) by Host_FileSystem

basically our forwarder disk space is getting filled because of  some specific intelligence logs..

here we want to highlight respective team that because of their logs its getting sudden surge logs..

 

 

 

Labels (1)
0 Karma

somesoni2
Revered Legend

What issues are you seeing with result? 

0 Karma

nmohammed
Contributor

@Susha 

Is your forwarder sending disk space data and are you able to see any data in index=os ? breakdown the search query into individual parts and check 

index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com
index=os sourcetype=df host=de1secsplfwd002.dc-r.security.vodafone.com
| strcat host '@' Filesystem Host_FileSystem

 

 

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...