<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Query to list top CPU consuming process when utilisation is greater than 70% in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212353#M176249</link>
    <description>&lt;P&gt;In order to form a query for this we should have a way to get all the servers which have greater than 70% CPU utilization and these servers should be searchable in index where you have process listed. If that is so you can proceed as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;outer search to get the host and process  [ inner search which will return the hosts which have greater than 70% CPU Utilization and will be used as search strings in outer query ]
| completing the outer search to get the top processes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In your example, I am thinking the field Server is what has hostname and should be searchable in outer query as a host:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index= infra earliest=-15m source="Perfmon:Process" counter="% Processor Time" (instance!="_Total" AND instance!="Idle" AND instance!="System")  
[| loadjob savedsearch="nobody:cdfs-infg:infra_saved_search"|stats latest(CPU) as CPU by Server
|eval CPU=round(CPU,2)
| dedup Server,CPU
| where CPU&amp;gt;70
| table Server  ]
| eventstats avg(Value) as AvgValue by host,instance | top instance by AvgValue,host limit=10 showperc=f showcount=f| sort -host,-AvgValue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;NOTE&lt;/STRONG&gt; In the inner query I have used all the calculations which were sufficient to calculate &lt;CODE&gt;| where CPU&amp;gt;70&lt;/CODE&gt;. If you need to calculate &lt;CODE&gt;total_memory&amp;gt;70&lt;/CODE&gt; as well then some tweaks might be needed.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Nov 2016 03:37:08 GMT</pubDate>
    <dc:creator>gokadroid</dc:creator>
    <dc:date>2016-11-05T03:37:08Z</dc:date>
    <item>
      <title>Splunk Query to list top CPU consuming process when utilisation is greater than 70%</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212352#M176248</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I have 2 queries, one to find top 10 CPU utilising process and 1 more for finding the avg CPU utilisation but I am not sure how to combine both of them in 1 query&lt;/P&gt;

&lt;P&gt;My requirement is, if CPU utilisation is greater than 70% then we must get the top 10 running process for those servers so that it will help us in troubleshooting in 1 report&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Query-1 : To get list of Top process&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;index= &lt;EM&gt;infra&lt;/EM&gt; earliest=-15m  source="Perfmon:Process"  counter="% Processor Time" (instance!="_Total" AND instance!="Idle" AND instance!="System") | eventstats avg(Value) as AvgValue by host,instance  | top instance by AvgValue,host  limit=10 showperc=f showcount=f| sort  -host,-AvgValue&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Query-2: Get the list of servers whose CPU utilisation is greater than 70%&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;| loadjob savedsearch="nobody:cdfs-infg:infra_saved_search"|stats latest(CPU) as CPU,latest(Memory) as Memory, latest(Swap) as Swap by Server | lookup inventory "Server Name" as Server OUTPUT "Application Name"&lt;BR /&gt;
 |table "Application Name",Server,CPU,Memory,Swap&lt;BR /&gt;
|eval CPU=round(CPU,2)| eval total_memory=round((Memory+Swap),2) |eval Swap=round(Swap,2)| dedup Server,CPU,Memory,Swap |  where CPU&amp;gt;70 OR total_memory&amp;gt;70 | sort - total_memory&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Can you please help ?&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Thank you so much !&lt;BR /&gt;
aparna&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212352#M176248</guid>
      <dc:creator>aparnaa</dc:creator>
      <dc:date>2020-09-29T11:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to list top CPU consuming process when utilisation is greater than 70%</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212353#M176249</link>
      <description>&lt;P&gt;In order to form a query for this we should have a way to get all the servers which have greater than 70% CPU utilization and these servers should be searchable in index where you have process listed. If that is so you can proceed as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;outer search to get the host and process  [ inner search which will return the hosts which have greater than 70% CPU Utilization and will be used as search strings in outer query ]
| completing the outer search to get the top processes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In your example, I am thinking the field Server is what has hostname and should be searchable in outer query as a host:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index= infra earliest=-15m source="Perfmon:Process" counter="% Processor Time" (instance!="_Total" AND instance!="Idle" AND instance!="System")  
[| loadjob savedsearch="nobody:cdfs-infg:infra_saved_search"|stats latest(CPU) as CPU by Server
|eval CPU=round(CPU,2)
| dedup Server,CPU
| where CPU&amp;gt;70
| table Server  ]
| eventstats avg(Value) as AvgValue by host,instance | top instance by AvgValue,host limit=10 showperc=f showcount=f| sort -host,-AvgValue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;NOTE&lt;/STRONG&gt; In the inner query I have used all the calculations which were sufficient to calculate &lt;CODE&gt;| where CPU&amp;gt;70&lt;/CODE&gt;. If you need to calculate &lt;CODE&gt;total_memory&amp;gt;70&lt;/CODE&gt; as well then some tweaks might be needed.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 03:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212353#M176249</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-11-05T03:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to list top CPU consuming process when utilisation is greater than 70%</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212354#M176250</link>
      <description>&lt;P&gt;I tried but I am getting no results found &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 03:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212354#M176250</guid>
      <dc:creator>aparnaa</dc:creator>
      <dc:date>2016-11-05T03:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to list top CPU consuming process when utilisation is greater than 70%</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212355#M176251</link>
      <description>&lt;P&gt;Check these:&lt;/P&gt;

&lt;P&gt;1) Are really servers running at 70% now? Can you try to lower that value to &lt;CODE&gt;| where CPU &amp;gt; 5&lt;/CODE&gt; and see if it returns something.&lt;/P&gt;

&lt;P&gt;2) Run inner query separately and see if you get values for Server fields.&lt;/P&gt;

&lt;P&gt;3) Is value of host field in outer query and value of Server from inner query similar?? Like if inner Server field has values like  "abc.domain.com", outer index field host should have values like "abc.domain.com" as well. Or at least the string "abc.domain.com" should be present in outer index events for outer query  to search it and return events.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 04:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212355#M176251</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-11-05T04:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to list top CPU consuming process when utilisation is greater than 70%</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212356#M176252</link>
      <description>&lt;P&gt;1) host and server have matching values, when i try them separately its working &lt;BR /&gt;
 2) its not working even when i take way the condition "where"&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 04:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212356#M176252</guid>
      <dc:creator>aparnaa</dc:creator>
      <dc:date>2016-11-05T04:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to list top CPU consuming process when utilisation is greater than 70%</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212357#M176253</link>
      <description>&lt;P&gt;Ok, interesting, maybe we are missing something...can you tweak this part of inner query as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dedup Server,CPU
| where CPU&amp;gt;70
 | table Server  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Change above lines to below lines to see if it actually returns something...and then complete your outer query.. this should work&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dedup Server,CPU
| where CPU&amp;gt;70
| return 10000 $Server  
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 05 Nov 2016 04:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-list-top-CPU-consuming-process-when-utilisation/m-p/212357#M176253</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-11-05T04:36:05Z</dc:date>
    </item>
  </channel>
</rss>

