Splunk Search

How can I produce results with a span of 1 day and span for every 1st of the month?

Gowtham0809
New Member

I User the below search to identify the usage of disk for 1 day(Previous day).

earliest=-2d index="A" source="PerfmonMk:Free Disk Space" "%_Free_Space"="*" E | eval volume=Free_Megabytes/1024 | chart avg(volume) | rename avg(volume) as Volume1 | join type=left [search earliest=-1d index="A" source="PerfmonMk:Free Disk Space" "%_Free_Space"="*" E | eval volume=Free_Megabytes/1024 | chart avg(volume) | rename avg(volume) as Volume2]  | eval difference=(Volume1-Volume2) 

I need to get this data on a daily basis to generate a monthly report.

Would someone help me in doing the same using the time span command?

Thanks,

Tags (3)
0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @Gowtham0809

Does this do what you are wanting:

earliest=-1mon@mon index="A" source="PerfmonMk:Free Disk Space" "%_Free_Space"="" E | eval volume=Free_Megabytes/1024 | timechart span=1d avg(volume) as volume

Hope this helps.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...