Getting Data In

CPU Utilization of Splunk Forwarder running on Linux machine showing wrong values

hishamjan
Explorer

Hi,

 

I have two servers running on Centos that have Universal Forwarder installed and I've enabled the following:

hishamjan_0-1617036544932.png

But using htop command on the servers, the CPU utilization is almost 100% but on splunk, it shows 20-30% at most.

 

Below is the query I used to find the CPU utilization for each available host:

host=* source="vmstat" | bucket span=300s _time | stats max(memUsedPct) as memUsedPct by _time host |  timechart span=300s max(memUsedPct) as "Used Memory Percentage" by host limit=0

 

Please, is there a way to resonate with the htop results?

Labels (4)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

You are asking about CPU utilization, but your search query is using memUsedPct (memory)....?

0 Karma

hishamjan
Explorer

hishamjan_0-1617043739633.png

this is the visualization of different hosts using the above query.

 

Hope this also gives you a better idea of what I'm achieving vs what I really wanna achieve.

0 Karma

hishamjan
Explorer

Hi, 

this is what I was getting in my search results.

please refer to the picture below:

hishamjan_0-1617043311559.png

 

Hope this gives you an idea about the memUsedPct (memory) I've indexed.

 

 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...