Splunk Search

How can I produce results with a span of 1 day and span for every 1st of the month?

Gowtham0809
New Member

I User the below search to identify the usage of disk for 1 day(Previous day).

earliest=-2d index="A" source="PerfmonMk:Free Disk Space" "%_Free_Space"="*" E | eval volume=Free_Megabytes/1024 | chart avg(volume) | rename avg(volume) as Volume1 | join type=left [search earliest=-1d index="A" source="PerfmonMk:Free Disk Space" "%_Free_Space"="*" E | eval volume=Free_Megabytes/1024 | chart avg(volume) | rename avg(volume) as Volume2]  | eval difference=(Volume1-Volume2) 

I need to get this data on a daily basis to generate a monthly report.

Would someone help me in doing the same using the time span command?

Thanks,

Tags (3)
0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @Gowtham0809

Does this do what you are wanting:

earliest=-1mon@mon index="A" source="PerfmonMk:Free Disk Space" "%_Free_Space"="" E | eval volume=Free_Megabytes/1024 | timechart span=1d avg(volume) as volume

Hope this helps.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...