Any ideas how to write a Splunk search to detect rapidly growing disk usage. Using a sourcetype of WinHostMon and the storage_used field?
That is what the ML toolkit is for:
https://docs.splunk.com/Documentation/MLApp/latest/User/SmartOutlierAssistant
Is there not a way to do it with the WinHostMon logs by writing a report based off of a search?