Splunk Search

How to estimate number of days left for disk to full?

venky1544
Builder

Hi 

i have dataset where data is ingested into  splunk once a day at 5PM everyday

Below is the dataset  USED_SPACE and TOTAL SPACE are in MB 

date=10/07/2023 17:00:00 drive=HD USED_SPACE=10 TOTAL_space=100

date=09/07/2023 17:00:00 drive=HD USED_SPACE=12 TOTAL_space=100

date=08/07/2023 17:00:00 drive=HD USED_SPACE=13 TOTAL_space=100

date=07/07/2023 17:00:00 drive=HD USED_SPACE=10 TOTAL_space=100

Based on the growth of the used_space per day i want to calculate the days left for the drive to reach TOTAL space basically in how many days would it reach for Total space need a separate column as days remaining 

 

Labels (1)
0 Karma

GaetanVP
Contributor

Hello @venky1544,

I do not understand 100% of your problem,

How exactly do you receive / ingest the data ? Once a day you will have a new line inside your dataset ? Would you be able to share a screenshot of a Splunk Search where you display those data ? 

Also I am surprise that your USED_SPACE does not grows from 07 to 10, it goes 10 to 13 to 10MB again ?

Regards,

GaetanVP

0 Karma

venky1544
Builder

Hi @GaetanVP 

the data is coming from a file. its once  a day so everyday you will have a new line appended to the file why the surprise, space in a drive doesn't mean it should always go linearly from 7  to 10. somedays some might copy total 13MB of files someday some might copy and delete so space in disk would change to 10MB 

i hope it clears your confusion

Thanks

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could use splunk to predict used disk space. See function predict from command documentation and there are some examples on net/community. 
r. Ismo 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...