I am able to display disk space via the Pie Chart visualization, but I'd like to display w/ a chart, like what's in this vmware dashboard:
http://blogs.splunk.com/wp-content/uploads/2012/06/splunkx_dash_02.jpg
host=host sourcetype="df" "/dev/sda2" | dedup host | chart
I think that's how I want to start, but don't know how to finish. Thanks much for any help.
Based on your last comment to my first answer, do this:
host=host sourcetype="df" "/dev/sda2" | dedup host | chart avg(PercentUsedSpace) by host
When you use table
it tells Splunk not to attempt a visualization whereas chart
implies a visualization and tells Splunk to attempt to do so.
Based on your last comment to my first answer, do this:
host=host sourcetype="df" "/dev/sda2" | dedup host | chart avg(PercentUsedSpace) by host
When you use table
it tells Splunk not to attempt a visualization whereas chart
implies a visualization and tells Splunk to attempt to do so.
Like this?
host=host sourcetype="df" "/dev/sda2" | dedup host | table *
Just about. That shows all the values for a df in the chart, which granted, is what I asked for. I guess what I'd really like to see is, on a scale of 100%, the used percentage of, say, /dev/sda2. I'm hoping to add multiple hosts to this query, and display each w/ a different color on the graph.
Thank you very much for your reply and assistance.
edit: I tried host=host sourcetype="df" "/dev/sda2" | dedup host | table PercentUsedSpace, which shows the correct value in statistics, but nothing in Visualization.