Splunk Search

Help with a search language that could determine full disks and system logins after core hours?

essibong1
New Member

Can any one help with a search language that could determine full disks and system logins after core hours?

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @essibong1,
did you already take the information on disks from your servers using TA_Windows and TA_nix or not?
If not, you have to install these TAs or enable the stanzas to read disks.

Then you have to run something like this for windows:

index=windows sourcetype=WinHostMon DriveType=fixed
| stats latest(TotalSpaceKB) AS TotalSpaceKB latest(FreeSpaceKB) AS FreeSpaceKB by host, Name 
| eval Perc=(FreeSpaceKB/TotalSpaceKB)*100, TotalSpaceGB=TotalSpaceKB/1024/1024, FreeSpaceGB=FreeSpaceKB/1024/1024, host=upper(host) 
| sort host
| table Name TotalSpaceGB FreeSpaceGB Perc
| rename host AS "Server Name" Name AS "Drive" Perc AS "FreeSpace%"

and for Linux

index=os sourcetype=hardware 
| dedup host
| eval host=upper(host)
| table HARD_DRIVES  fd0 hdc sda
| rename HARD_DRIVES AS "Hard Disks" fd0 AS "Floppy Disk" hdc AS "Hard Disk" sda AS "Virtual disk"

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...