(index=windows OR index=perfmon OR index=os) sourcetype=perfmonMK:LogicalDisk instance!=_Total instance!=Harddisk* | eval FreePct-Other=case( match (instance, "C:"), null(), match(instance,"D:"), null(),true(),storage_free_percent), FreeMB-Other=case( match (instance, "C:"), null(), match(instance,"D:"), null(), true(),Free_Megabytes), FreePct-{instance}=storage_free_percent,FreeMB-{instance}=Free_Megabytes
0 comments
| rest splunk_server=local /services/server/info | table host host_fqdn host_resolved
0 comments
| rest /servicesNS/-/-/admin/directory count=0 splunk_server=local | rename eai:* as *, acl.* as * | eval updated=strptime(updated,"%Y-%m-%dT%H:%M:%S%Z"), updated=if(isnull(updated),"Never",strftime(updated,"%d %b %Y"))| sort type | stats list(title) as title, list(type) as type, list(orphaned) as orphaned, list(sharing) as sharing, list(owner) as owner, list(updated) as updated by app
0 comments
| rest /services/server/status/partitions-space | eval diskFree=tostring(round(free/capacity,4)*100)."%", capacityGB=round(capacity/1024,2), freeGB=round(free/2014,2) | table splunk_server, mount_point, freeGB, capacityGB, diskFree | rename splunk_server as "Splunk Server", mount_point as "Mount Point", diskFree as "Disk Free (%)", freeGB as "Disk Free (GB)", capacityGB as "Capacity (GB)"
0 comments
| rest /services/authentication/users | stats values(roles) as Roles by title | rename title as User
0 comments
| rest splunk_server=* /services/data/indexes | eval "Retention Period (days)"=frozenTimePeriodInSecs/60/60/24 | table title "Retention Period (days)" | rename title as Index
0 comments
| rest /services/authentication/users | stats values(roles) as Role first(defaultApp) as "Default App" by title | rename title as Username
0 comments
| tstats values(sourcetype) as sourcetype WHERE index=* OR index=_* by index
0 comments
| rest /services/data/indexes | eval indexSize=tostring(round(currentDBSizeMB/1024,2), "commas"), events=tostring(totalEventCount, "commas"), daysRetention=frozenTimePeriodInSecs/60/60/24 | foreach *Time [ | eval <<FIELD>>=strptime(<<FIELD>>,"%Y-%m-%dT%H:%M:%S%Z"), <<FIELD>>=strftime(<<FIELD>>,"%m/%d/%Y %H:%M:%S") ] | fillnull value="n/a" | table title, splunk_server, indexSize, daysRetention, events, maxTime, minTime | rename title as "Index Name", splunk_server as "Splunk Server" indexSize as "Current Size on Disk (GB)", daysRetention as "Retention Period in Days", events as "Count of events", maxTime as "Most Recent Event", minTime as "Earliest Event"
0 comments
| rest /services/server/info | eval secUp=now()-startup_time, minutesUp=secUp/60 | table serverName, server_roles, secUp, minutesUp | rename serverName as "Splunk Server", server_roles as "Server Roles", secUp as "Uptime (sec)", minutesUp as "Uptime (min)"
0 comments