Dashboards & Visualizations

Gauge Not Showing Correct Number?

pmacdonald
Explorer

I have the following that should display the current free memory in a windows system. However, it appears that I am missing something.

 

index="perfmonmemory" | eval mem_free=mem_free/1024 | eval mem_free=round(mem_free,0) | timechart count span=1min | bin _time span=1min | stats avg(mem_free) as rpm | gauge rpm 10 20 30 40 50 60
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

A bunch of things wrong with that search.

You are not looking for a time series, so no point in timechart.

Your timechart is just calculating count, so when you try to use mem_free after the timechart, that field is no longer present.

You are using 'bin' command, which is about splicing by time, but you're not actually using _time in your stats - if you want to bin by _time with stats, then you do stats ... by _time after the bin.

This should get you to what you want

index="perfmonmemory" 
| eval mem_free=mem_free/1024 
| eval mem_free=round(mem_free,0) 
| stats avg(mem_free) as rpm 
| gauge rpm 10 20 30 40 50 60

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

A bunch of things wrong with that search.

You are not looking for a time series, so no point in timechart.

Your timechart is just calculating count, so when you try to use mem_free after the timechart, that field is no longer present.

You are using 'bin' command, which is about splicing by time, but you're not actually using _time in your stats - if you want to bin by _time with stats, then you do stats ... by _time after the bin.

This should get you to what you want

index="perfmonmemory" 
| eval mem_free=mem_free/1024 
| eval mem_free=round(mem_free,0) 
| stats avg(mem_free) as rpm 
| gauge rpm 10 20 30 40 50 60

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...