Im very lost setting up an alert with timechart in the search.
This is my search:
index=os sourcetype=df MountedOn="/var/opt/" | table * | timechart avg(PercentUsedSpace) by MountedOn
I would like to get the percentage of the disk and would like to be able to setup an alert if it goes above 85%.
Thanks 🙂
Try changing your search to only return results that meet your alert threshold:
index=os sourcetype=df MountedOn="/var/opt/" | stats latest(PercentUsedSpace) AS latest_pct_used by MountedOn | search latest_pct_used>85
And as shown above, you probably don't care about the average, so much as you care about the last known percent used.