Splunk Search

Help on formula

jip31
Motivator

hi

i use this code to monitore the hdd free space
index="perfmon" sourcetype="perfmon:logicaldisk" instance=c: counter="% Free Space" | eval Value = round(Value, 2). "%" |table _time host Value
but this code give me the free space and not the buzy space
i have 89% free so i would to have instead 11% busy
how can i do please??

Tags (1)
0 Karma
1 Solution

p_gurav
Champion

Can you try subtracting free space from 100. Like, |eval Value=100-round(Value)

View solution in original post

0 Karma

jip31
Motivator

thanks it works!

0 Karma

p_gurav
Champion

Can you try subtracting free space from 100. Like, |eval Value=100-round(Value)

0 Karma
Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...