Splunk Search

Monitoring disk space

steveo2
Engager

Hi,  I'm using the following search to monitor disk space.  I have 2 partitions, drive D and E.  I am only returning results for drive D.  I would have expected results for both.  Any thoughts are appreciated. thanks


| rest splunk_server=Splunk01 /services/server/status/partitions-space | eval free = if(isnotnull(available), available, free) | eval usage = round((capacity - free) / 1024, 2) | eval capacity = round(capacity / 1024, 2) | eval compare_usage = usage." / ".capacity | eval pct_usage = round(usage / capacity * 100, 2) | stats first(fs_type) as fs_type first(compare_usage) as compare_usage first(pct_usage) as pct_usage by mount_point | rename mount_point as "Mount Point", fs_type as "File System Type", compare_usage as "Disk Usage (GB)", capacity as "Capacity (GB)", pct_usage as "Disk Usage (%)" 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

When you run the rest command by itself, do you see both mount points?

BTW, the rename command references the capacity field, but that field was discarded by stats.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

When you run the rest command by itself, do you see both mount points?

BTW, the rename command references the capacity field, but that field was discarded by stats.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...