All Apps and Add-ons

Process usage by host

jackpal
Path Finder

We are tracking Linux process usage across several hosts which are tagged. I can get an overall usage by process across all hosts combined but I'd like to separate this out by host for alerting purposes.

My query so far:
index=os OR index=main sourcetype=ps tag=dcv COMMAND="gnome-shell" | stats sum(pctCPU) as pctCPU by _time,COMMAND | timechart avg(pctCPU) by COMMAND

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If COMMAND is fixed, there's no need for it in the by clause. Try this query.

index=os OR index=main sourcetype=ps tag=dcv COMMAND="gnome-shell" | stats sum(pctCPU) as pctCPU by _time,host | timechart avg(pctCPU) by host
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...