Splunk Search

How do I run forecast time series multiple times using one search?

mtmoore
Explorer

I want to run a forecast time series multiple times using one search on the remaining freespace of a number of our databases (data collected on within Splunk) — in this case, around 900 with 5 days worth of historical data — predicting whether the freespace will run below 60% in the next 90 days. I can use the map command, but it just times out after about an hour... any suggestions?

sourcetype="mysource" | stats count by Database| map search="search sourcetype=mysource Database=$Database$   |  timechart span=24h avg(MainPercFree)  | fit ARIMA _time avg(MainPercFree) order=1-0-0 forecast_k=90 holdback=0 conf_interval=95 as prediction |where prediction < 60 | stats earliest(_time) as First |eval Database=$Database$" maxsearches=900 |eval First=strftime(First,"%+")
0 Karma

mtmoore
Explorer

I'm afraid those articles don't show how to predict values on multiple fields of data 😞

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...