This seems so close. I just have to choose a mount on my linux systems, otherwise the data is pointless. This is what I have
index=nix sourcetype=df host=myHost10 * OR host=myHost20*
| stats first(PercentUsedSpace) as pctUsed latest(Avail) as Avail by host, Filesystem, filesystem_type, Size, Used, MountedOn
| where (like(MountedOn,"%") AND pctUsed > 90) OR (like(MountedOn,"home/work%") AND pctUsed > 95)
| sort - pctUsed
it's showing me weird results though. It's only showing me the machines that have 'home/work' mount ABOVE 90%.
Update, the last statement was my own stupidity, please ignore that. 🙂 It's just not filtering out the >95%.
I think my filter is too vauge.
... View more