I'm new to Splunk and need some help with a chart for disk space usage. I'm getting the data already in Splunk Light and would like to do a line chart that displays ALL servers and ALL drives in the same chart.
Thanks for your help.
Depends upon what you want to plot as x-axis value and what as series, try something like this (check the sourcetype name is correct or not)
host on x-axis, and one line for each drive
index=foo sourcetype="Perfmon:Logical Disk"
| chart avg(Value) over host by instance limit=0
drive on x-axis, and one line for each host
index=foo sourcetype="Perfmon:Logical Disk"
| chart avg(Value) over instance by host limit=0 | rename instance as drive
Depends upon what you want to plot as x-axis value and what as series, try something like this (check the sourcetype name is correct or not)
host on x-axis, and one line for each drive
index=foo sourcetype="Perfmon:Logical Disk"
| chart avg(Value) over host by instance limit=0
drive on x-axis, and one line for each host
index=foo sourcetype="Perfmon:Logical Disk"
| chart avg(Value) over instance by host limit=0 | rename instance as drive
Thanks for your help. This is what I was looking for.
Sample events please.
yes, please post what you have (code and a sample event) so we can be of most help.
Regular events from perfmon for example:
collection="Free Disk Space"
object=LogicalDisk
counter="% Free Space"
instance=C:
Value=30.601598715187794
host = server1
collection="Free Disk Space"
object=LogicalDisk
counter="% Free Space"
instance=C:
Value=63.5187794
host = server2
server1 has 3 drive letters C:, E:, F:.
server 2 has 1 drive letter C:
server 3 has 3 drive letters C:, D:, E: