In my scenario the indexer is working but diskspace is 100% in /splunk/data1.when i used source=df i dint see the mentioned path in the result .how to find and set alert for the particular path.