<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create visualizations by using Unix top command output? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240955#M14946</link>
    <description>&lt;P&gt;For uptime, you do not &lt;CODE&gt;multikv&lt;/CODE&gt;, just send the entire output in as a single event and use a field extraction like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "(?&amp;lt;time&amp;gt;.*)\s+up\s+(?&amp;lt;updays&amp;gt;.*)\s+days,\s+(?&amp;lt;uphours&amp;gt;\d+):(?&amp;lt;upminutes&amp;gt;\d+),\s+(?&amp;lt;num_users&amp;gt;\d+)\s+users,\s+load\s+average:\s+(?&amp;lt;avgload_1minute&amp;gt;.+),\s+(?&amp;lt;avgload_5minutes&amp;gt;.+),\s+(?&amp;lt;avgload_15minutes&amp;gt;.+)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 20 Jan 2017 06:01:43 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-01-20T06:01:43Z</dc:date>
    <item>
      <title>How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240945#M14936</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
i have a cronjob which has some performance related scripts which run for every 5 mins and sends output to indexed folder.&lt;/P&gt;

&lt;P&gt;attaching the top command output: &lt;A href="https://answers.splunk.comstorage/temp/177228-top.txt"&gt;link text&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I'd like respective graphs using Unix top command output. How can we create the visualizations by using top output? any help is appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 19:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240945#M14936</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-17T19:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240946#M14937</link>
      <description>&lt;P&gt;can we show them based on top output like&lt;/P&gt;

&lt;P&gt;total memory&lt;BR /&gt;
used memory&lt;BR /&gt;
free and cached&lt;BR /&gt;
total swap&lt;BR /&gt;
used swap&lt;BR /&gt;
free and buffered swap&lt;/P&gt;

&lt;P&gt;top users consumed CPU,memory and PID&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 20:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240946#M14937</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-17T20:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240947#M14938</link>
      <description>&lt;P&gt;Is the output of whole command available in Splunk as part of one event?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 20:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240947#M14938</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-01-17T20:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240948#M14939</link>
      <description>&lt;P&gt;No,&lt;BR /&gt;
when i index the output,i selected source type as generic_single_line,so its displaying each line as one event.&lt;/P&gt;

&lt;P&gt;i am not very sure,which one is good for displaying like total output as one event or each line as one event.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240948#M14939</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2020-09-29T12:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240949#M14940</link>
      <description>&lt;P&gt;will it work if i make it as one event?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 22:37:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240949#M14940</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-17T22:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240950#M14941</link>
      <description>&lt;P&gt;First make sure that each run's output is treated as a single event:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.1/Data/Configureeventlinebreaking"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.1/Data/Configureeventlinebreaking&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then use &lt;CODE&gt;multikv&lt;/CODE&gt; to create multiple events from that:&lt;BR /&gt;
&lt;A href="http://blogs.splunk.com/2007/08/23/ripping-mulitline-events-at-seach-time/"&gt;http://blogs.splunk.com/2007/08/23/ripping-mulitline-events-at-seach-time/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Multikv"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Multikv&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2017 00:06:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240950#M14941</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-01-18T00:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240951#M14942</link>
      <description>&lt;P&gt;thank you,i am checking and working on it,i will update on this thread once i implement the same&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2017 00:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240951#M14942</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-18T00:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240952#M14943</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
i am working on uptime command.can we show below uptime load average results in line chart?&lt;/P&gt;

&lt;P&gt;13:43:55 up 74 days,  4:08,  2 users,  load average: 0.11, 0.05, 0.01&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2017 21:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240952#M14943</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-19T21:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240953#M14944</link>
      <description>&lt;P&gt;i have written a script which display output like below.can we create any kind of chart with below out put&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2017 22:30:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240953#M14944</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-19T22:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240954#M14945</link>
      <description>&lt;P&gt;Post the output of the script here.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 04:53:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240954#M14945</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-01-20T04:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240955#M14946</link>
      <description>&lt;P&gt;For uptime, you do not &lt;CODE&gt;multikv&lt;/CODE&gt;, just send the entire output in as a single event and use a field extraction like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "(?&amp;lt;time&amp;gt;.*)\s+up\s+(?&amp;lt;updays&amp;gt;.*)\s+days,\s+(?&amp;lt;uphours&amp;gt;\d+):(?&amp;lt;upminutes&amp;gt;\d+),\s+(?&amp;lt;num_users&amp;gt;\d+)\s+users,\s+load\s+average:\s+(?&amp;lt;avgload_1minute&amp;gt;.+),\s+(?&amp;lt;avgload_5minutes&amp;gt;.+),\s+(?&amp;lt;avgload_15minutes&amp;gt;.+)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Jan 2017 06:01:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240955#M14946</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-01-20T06:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240956#M14947</link>
      <description>&lt;P&gt;Thank you,I was not able to copy my output.&lt;/P&gt;

&lt;P&gt;Usually when we run uptime command in Linux it shows load average with 3 values delimited by a comma.&lt;BR /&gt;
Can we visualize these load average values in any kind of chart.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 06:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240956#M14947</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-20T06:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to create visualizations by using Unix top command output?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240957#M14948</link>
      <description>&lt;P&gt;You can then add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | timechart avg(avgload*) BY host
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Jan 2017 06:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-visualizations-by-using-Unix-top-command-output/m-p/240957#M14948</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-01-20T06:31:29Z</dc:date>
    </item>
  </channel>
</rss>

