All Apps and Add-ons

Find total MB in use based on '% Committed in Bytes' and 'Committed Bytes'

bcyates
Communicator

Hi all,

My fields looks like this:

CommittedBytes=1610014720
PagesPersec=0
PercentCommittedBytesInUse=27
wmi_type=Memory

I can see my total CommittedBytes and my PercentCommittedBytesInUse. But what I need is MB in use instead of just the percentage. Does anyone know a good way to do the math on the conversion?

1 Solution

mayurr98
Super Champion

you should do something like this

| eval CommittedBytes_MB=round(CommittedBytes/1000000,2)

In more accurate way you should try

| eval CommittedBytes(MB) = round(CommittedBytes/1024/1024,2)

let me know if this helps!

View solution in original post

0 Karma

mayurr98
Super Champion

you should do something like this

| eval CommittedBytes_MB=round(CommittedBytes/1000000,2)

In more accurate way you should try

| eval CommittedBytes(MB) = round(CommittedBytes/1024/1024,2)

let me know if this helps!

0 Karma

mayurr98
Super Champion

Okay so this is still achievable using simple math.

Step1:Calculate UsedBytes
(UsedBytes/CommittedBytes)*100=PercentCommittedBytesInUse

Step2 : convert bytes to MB

UsedBytes/1024/1024

Try this search query

| eval UsedBytes=(PercentCommittedBytesInUse/100)*CommittedBytes | eval UsedMB=UsedBytes/1024/1024

Let me know if this helps!

bcyates
Communicator

This is great, thanks!

0 Karma

anjambha
Communicator

Hi bcyates,

Are you looking for something like.
CommittedBytes(MB) = CommittedBytes/1000000

= 1610014720/1000000
= 1610.01472 MB

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...