Get the Splunk for Microsoft Windows app and that will get you all the field extractions and dashboard views. Then you'll be able to run a search like this for your alert. Or you'll also find examples based on percentages i'm sure as well.
sourcetype="WMI:FreeDiskSpace" host=some_server Name="C:" FreeMegabytes < 2048
What do the events that you're triggering on look like? Splunk doesn't have specific values for disk space etc because it is agnostic about such things - it just "sees" values, it's up to you to provide the intelligence for the alert thresholds.