Splunk Search

Calculate disk space growth over time

jackpal
Path Finder

I am providing summarized reports on disk space over several hosts using this query:

index=os sourcetype=df host=host1 OR host=host2

| eval CPD_Disk=case(
filesystem LIKE "%gas%", "Gas Volume",
filesystem LIKE "%cadbas%", "CMS Volume",
filesystem LIKE "%spg%", "SPG Volume",
filesystem LIKE "%gen%", "Generator Volume",
filesystem LIKE "%stm%", "Steam Volume"
)
| chart eval(sum(UsedMBytes)/1024/1024) as TerraBytes by CPD_Disk| addcoltotals TerraBytes labelfield=CPD_Disk label=Total

I would like to provide the total amount of growth over the past 30 days. How could I add something like this ?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...