I'm building a dashboard to monitor usage of a tool called Datameer. Logs are captured by two dedicated queues in YARN canned 'Ad-hoc' and 'Scheduled'.
I need to plot a graph showing usage of these two queues over a period of 24 hours. Is there a way within Splunk to plot usage metrics for a field over a period of time?
Try something like this
index=xyz YARN='Ad-hoc' OR YARN="Scheduled" | timechart span=1h count by YARN
Thank you Sundar..
I have this search query :
index="prod_hadoop" sourcetype=yarn host="asphad301.aus1.homeaway.live" AND ( queue=datameer OR queue=dm-adhoc: OR queue=dm-scheduled:) | Table queue absoluteUsedCapacity
I need to plot graph of used capacity percentage over past 24 hours.. Is there a way to extend above query..