Splunk Search

Calculate disk space growth over time

jackpal
Path Finder

I am providing summarized reports on disk space over several hosts using this query:

index=os sourcetype=df host=host1 OR host=host2

| eval CPD_Disk=case(
filesystem LIKE "%gas%", "Gas Volume",
filesystem LIKE "%cadbas%", "CMS Volume",
filesystem LIKE "%spg%", "SPG Volume",
filesystem LIKE "%gen%", "Generator Volume",
filesystem LIKE "%stm%", "Steam Volume"
)
| chart eval(sum(UsedMBytes)/1024/1024) as TerraBytes by CPD_Disk| addcoltotals TerraBytes labelfield=CPD_Disk label=Total

I would like to provide the total amount of growth over the past 30 days. How could I add something like this ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...