Splunk Search

Calculate disk space growth over time

jackpal
Path Finder

I am providing summarized reports on disk space over several hosts using this query:

index=os sourcetype=df host=host1 OR host=host2

| eval CPD_Disk=case(
filesystem LIKE "%gas%", "Gas Volume",
filesystem LIKE "%cadbas%", "CMS Volume",
filesystem LIKE "%spg%", "SPG Volume",
filesystem LIKE "%gen%", "Generator Volume",
filesystem LIKE "%stm%", "Steam Volume"
)
| chart eval(sum(UsedMBytes)/1024/1024) as TerraBytes by CPD_Disk| addcoltotals TerraBytes labelfield=CPD_Disk label=Total

I would like to provide the total amount of growth over the past 30 days. How could I add something like this ?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...