Splunk Search

search string

Splunk_U
Path Finder

Is there any thing wrong with the below search string?????

index=os source=df |multikv fields Filesystem Avail UsePct | search Filesystem=/dev/mapper/system-root | eval availPct=(100-UsePct) | stats avg(Avail) as availDisk avg(availPct) as UsePct by host

Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee

Verify is UsePct is a string or a number.
use | convert num(UsePct) if needed

0 Karma

Ayn
Legend

What format are the values for Avail in? If avg() doesn't return anything even though Avail has values, it indicates that the Avail values aren't something that avg() can treat as numbers.

0 Karma

Splunk_U
Path Finder

Till the below portion it is working fine..

index=os source=df |multikv fields Filesystem Avail UsePct | search Filesystem=/dev/mapper/system-root

then when I am adding "stats avg(Avail) as availDisk by host" it is not fetching any data...where as if I add "stats values(Avail) as availDisk by host" then the data is coming...

Any thought!!!

0 Karma

sdaniels
Splunk Employee
Splunk Employee

It usually makes sense to break down your search and track when you are getting data and then where you aren't getting what you expect. Start with the beginning and then add additional commands one by one to see where the search is breaking down.

0 Karma

Splunk_U
Path Finder

I am getting no result...but it should provide me the avg available disk info and and avg available percentage..Am I missing something in syntax???

0 Karma

Ayn
Legend

I assume there's a reason for asking? What results are you currently getting?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...