Getting Data In

CPU Utilization of Splunk Forwarder running on Linux machine showing wrong values

hishamjan
Explorer

Hi,

 

I have two servers running on Centos that have Universal Forwarder installed and I've enabled the following:

hishamjan_0-1617036544932.png

But using htop command on the servers, the CPU utilization is almost 100% but on splunk, it shows 20-30% at most.

 

Below is the query I used to find the CPU utilization for each available host:

host=* source="vmstat" | bucket span=300s _time | stats max(memUsedPct) as memUsedPct by _time host |  timechart span=300s max(memUsedPct) as "Used Memory Percentage" by host limit=0

 

Please, is there a way to resonate with the htop results?

Labels (4)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

You are asking about CPU utilization, but your search query is using memUsedPct (memory)....?

0 Karma

hishamjan
Explorer

hishamjan_0-1617043739633.png

this is the visualization of different hosts using the above query.

 

Hope this also gives you a better idea of what I'm achieving vs what I really wanna achieve.

0 Karma

hishamjan
Explorer

Hi, 

this is what I was getting in my search results.

please refer to the picture below:

hishamjan_0-1617043311559.png

 

Hope this gives you an idea about the memUsedPct (memory) I've indexed.

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...