<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search query for permon counter in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157249#M44257</link>
    <description>&lt;P&gt;You can use "|sort 0 host, counter, Value" to sort more than 10000 rows.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2014 14:43:22 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-10-09T14:43:22Z</dc:date>
    <item>
      <title>Search query for permon counter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157248#M44256</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;we had configured splunk to get the perfmon counter data from server (every 5mins). The counter value gets reset frequently. &lt;/P&gt;

&lt;P&gt;We found that raw data is not coming in the Order (time sorted). And some time the counter value is getting incremented with in second as shown below.  we cann't use sort . it limits for 10,000 (as per standard conf). we are receiving more then 10 lak events per day in perfmon &lt;/P&gt;

&lt;P&gt;data is comes like below per sec &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Date Server counter Value

09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3932     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3929     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3937
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Expected : &lt;/P&gt;

&lt;P&gt;We are expecting as below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Date Server counter Value

09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3937     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3932     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3929
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We are using Stream stats to calculate the total capture message per day.&lt;/P&gt;

&lt;P&gt;Query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=win_srv_perf (object="XXXXXXXXXXX") counter="XXXXXXXXXX" host="XXXXXXXXXX"| eval Time = strftime(_time,"%m_%d_%Y_%H_%M_%S") | streamstats current=f last(Value) as newValue by host counter | eval msgDiff=(if(newValue&amp;gt;=Value,newValue-Value,newValue)) | table Time DumID host counter Value newValue msgDiff | stats sum(msgDiff) as value by host counter
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 09 Oct 2014 12:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157248#M44256</guid>
      <dc:creator>rsathish47</dc:creator>
      <dc:date>2014-10-09T12:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Search query for permon counter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157249#M44257</link>
      <description>&lt;P&gt;You can use "|sort 0 host, counter, Value" to sort more than 10000 rows.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 14:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157249#M44257</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-10-09T14:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Search query for permon counter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157250#M44258</link>
      <description>&lt;P&gt;Thanks Somesoni2.. It worked &lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2014 06:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-query-for-permon-counter/m-p/157250#M44258</guid>
      <dc:creator>rsathish47</dc:creator>
      <dc:date>2014-10-13T06:05:46Z</dc:date>
    </item>
  </channel>
</rss>

