<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to write a search query for CPU in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/586945#M13532</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to create a alert for cpu usage by using below query,&lt;/P&gt;&lt;PRE&gt;index=os host=cbtsv &lt;BR /&gt;| stats latest(*) as * by host&lt;BR /&gt;| table _time cpu_load_percent cpu_user_percent &lt;BR /&gt;| eval CPU=cpu_load_percent+cpu_user_percent|stats avg(CPU) as percent by host&lt;/PRE&gt;&lt;P&gt;here Ii am trying to add 2 fields (CPU=CPU load + cpu user)&lt;BR /&gt;but it is not giving results as expected&lt;BR /&gt;I want an alert to be triggered when Avg value of CPU=(cpu_load + cpu user) exceeds 90%.&lt;BR /&gt;How do I set the alert to meet the conditions above?&lt;BR /&gt;&lt;BR /&gt;Final output like&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Timestamp&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Hostname&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;CPU&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;28/02/2022 21:58:00&lt;/TD&gt;&lt;TD&gt;cbtsv&lt;/TD&gt;&lt;TD&gt;90%&lt;/TD&gt;&lt;TD&gt;Critical&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2022 08:49:20 GMT</pubDate>
    <dc:creator>jackin</dc:creator>
    <dc:date>2022-03-01T08:49:20Z</dc:date>
    <item>
      <title>How to write a search query for CPU</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/586945#M13532</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to create a alert for cpu usage by using below query,&lt;/P&gt;&lt;PRE&gt;index=os host=cbtsv &lt;BR /&gt;| stats latest(*) as * by host&lt;BR /&gt;| table _time cpu_load_percent cpu_user_percent &lt;BR /&gt;| eval CPU=cpu_load_percent+cpu_user_percent|stats avg(CPU) as percent by host&lt;/PRE&gt;&lt;P&gt;here Ii am trying to add 2 fields (CPU=CPU load + cpu user)&lt;BR /&gt;but it is not giving results as expected&lt;BR /&gt;I want an alert to be triggered when Avg value of CPU=(cpu_load + cpu user) exceeds 90%.&lt;BR /&gt;How do I set the alert to meet the conditions above?&lt;BR /&gt;&lt;BR /&gt;Final output like&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Timestamp&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Hostname&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;CPU&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;28/02/2022 21:58:00&lt;/TD&gt;&lt;TD&gt;cbtsv&lt;/TD&gt;&lt;TD&gt;90%&lt;/TD&gt;&lt;TD&gt;Critical&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 08:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/586945#M13532</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-03-01T08:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search query for CPU</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/586946#M13533</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you're taking logs using the Splunk_TA-nix.&lt;/P&gt;&lt;P&gt;Anyway, please try a search like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=os host=cbtsv 
| stats avg(cpu_load_percent) as cpu_load_percent avg(cpu_user_percent) AS cpu_user_percent BY host
| eval CPU=cpu_load_percent+cpu_user_percent
| table host CPU&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 08:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/586946#M13533</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-01T08:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search query for CPU</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/587020#M13534</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=os host=cbtsv 
| table _time cpu_load_percent cpu_user_percent 
| stats max(_time) as _time avg(cpu_load_percent) as cpu_load_percent avg(cpu_user_percent) AS cpu_user_percent 
 by host
| eval CPU=cpu_load_percent+cpu_user_percent 
| where CPU&amp;gt;90 | eval Status="Critical" | eval CPU=CPU."%" rename host as Hostname
| table _time Hostname CPU Status&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 01 Mar 2022 14:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-write-a-search-query-for-CPU/m-p/587020#M13534</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-03-01T14:37:45Z</dc:date>
    </item>
  </channel>
</rss>

