<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help on a complex timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480473#M134647</link>
    <description>&lt;P&gt;Try something like &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; `CPU`   
 | eval hourmin = strftime(_time, "%H%M")
 | where (hourmin &amp;gt;= 800 AND hourmin &amp;lt;= 1700)
  | timechart span=1h avg(process_cpu_used_percent) as cpu_average by host 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 28 Feb 2020 16:22:29 GMT</pubDate>
    <dc:creator>sumanssah</dc:creator>
    <dc:date>2020-02-28T16:22:29Z</dc:date>
    <item>
      <title>help on a complex timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480470#M134644</link>
      <description>&lt;P&gt;hi&lt;BR /&gt;
I use the  search below in order to display a timechart which count the number of host which are in a cpu range consumption (0 - 20, 20 -40, 40 - 60)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; `CPU`   earliest=-30d latest=now 
| fields process_cpu_used_percent host 
| eval cpu_range=case(process_cpu_used_percent&amp;gt;0 AND process_cpu_used_percent &amp;lt;=20,"0-20",
    process_cpu_used_percent&amp;gt;20 AND process_cpu_used_percent &amp;lt;=40,"20-40",
    process_cpu_used_percent&amp;gt;40 AND process_cpu_used_percent &amp;lt;=60,"40-60")
| timechart span=1d dc(host) as host by cpu_range 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I need to changes :&lt;BR /&gt;
1) Instead counting the number of process_cpu_used_percent by host in a cpu range, I need to count the number of the process_used_percent &lt;STRONG&gt;average&lt;/STRONG&gt; by host in a cpu range&lt;BR /&gt;
2) Is is possible to take only the evnts which are in a specific slot time? (between 8h and 17h)&lt;BR /&gt;
thanks a lot for your help&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480470#M134644</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2020-09-30T04:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: help on a complex timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480471#M134645</link>
      <description>&lt;P&gt;Give this a try: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; `CPU`   earliest=-17h latest=-8h 
 | fields process_cpu_used_percent host 
 | eval cpu_range=case(process_cpu_used_percent&amp;gt;0 AND process_cpu_used_percent &amp;lt;=20,"0-20",
     process_cpu_used_percent&amp;gt;20 AND process_cpu_used_percent &amp;lt;=40,"20-40",
     process_cpu_used_percent&amp;gt;40 AND process_cpu_used_percent &amp;lt;=60,"40-60")
 | timechart span=1h avg(process_cpu_used_percent) as cpu_average by host 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 16:01:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480471#M134645</guid>
      <dc:creator>13tsavage</dc:creator>
      <dc:date>2020-02-28T16:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: help on a complex timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480472#M134646</link>
      <description>&lt;P&gt;Side note, you would not need the &lt;CODE&gt;| fields process_cpu_used_percent host&lt;/CODE&gt; line. The timechart would give you the exact output you want.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 16:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480472#M134646</guid>
      <dc:creator>13tsavage</dc:creator>
      <dc:date>2020-02-28T16:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: help on a complex timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480473#M134647</link>
      <description>&lt;P&gt;Try something like &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; `CPU`   
 | eval hourmin = strftime(_time, "%H%M")
 | where (hourmin &amp;gt;= 800 AND hourmin &amp;lt;= 1700)
  | timechart span=1h avg(process_cpu_used_percent) as cpu_average by host 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Feb 2020 16:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480473#M134647</guid>
      <dc:creator>sumanssah</dc:creator>
      <dc:date>2020-02-28T16:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: help on a complex timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480474#M134648</link>
      <description>&lt;P&gt;earliest=-17h latest=-8h  is not good because if I am doing this i have just the vents for one day instead 7 days like i need....&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 06:28:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-a-complex-timechart/m-p/480474#M134648</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2020-03-02T06:28:37Z</dc:date>
    </item>
  </channel>
</rss>

