Dashboards & Visualizations

Gauge Not Showing Correct Number?

pmacdonald
Explorer

I have the following that should display the current free memory in a windows system. However, it appears that I am missing something.

 

index="perfmonmemory" | eval mem_free=mem_free/1024 | eval mem_free=round(mem_free,0) | timechart count span=1min | bin _time span=1min | stats avg(mem_free) as rpm | gauge rpm 10 20 30 40 50 60
Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

A bunch of things wrong with that search.

You are not looking for a time series, so no point in timechart.

Your timechart is just calculating count, so when you try to use mem_free after the timechart, that field is no longer present.

You are using 'bin' command, which is about splicing by time, but you're not actually using _time in your stats - if you want to bin by _time with stats, then you do stats ... by _time after the bin.

This should get you to what you want

index="perfmonmemory" 
| eval mem_free=mem_free/1024 
| eval mem_free=round(mem_free,0) 
| stats avg(mem_free) as rpm 
| gauge rpm 10 20 30 40 50 60

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

A bunch of things wrong with that search.

You are not looking for a time series, so no point in timechart.

Your timechart is just calculating count, so when you try to use mem_free after the timechart, that field is no longer present.

You are using 'bin' command, which is about splicing by time, but you're not actually using _time in your stats - if you want to bin by _time with stats, then you do stats ... by _time after the bin.

This should get you to what you want

index="perfmonmemory" 
| eval mem_free=mem_free/1024 
| eval mem_free=round(mem_free,0) 
| stats avg(mem_free) as rpm 
| gauge rpm 10 20 30 40 50 60

 

Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...