Getting Data In

Help with extracting the fields and related data from vmstat logs which are coming into Splunk

rohit1793
SplunkTrust
SplunkTrust

Hi All,

Can you please help me to extract the fields and related data from vmstat logs which are coming into splunk,Below the logs lines:

memTotalMB memFreeMB memUsedMB memFreePct memUsedPct pgPageOut swapUsedPct pgSwapOut cSwitches interrupts forks processes threads loadAvg1mi waitThreads interrupts_PS pgPageIn_PS pgPageOut_PS
7000 xx8 xxx5 9.4 90.6 1561978416 100.0 85616943 4002987866 3965557908 66831877 250 3251 11.04 9.04 27902.02 48.24 2132.66

Rohit Joshi
Splunk Architect
Tags (1)
0 Karma
1 Solution

rohit1793
SplunkTrust
SplunkTrust

There is a command multikv, it works for tabled data like we get from Unix/Linux machines:

index=foo host=abc* sourcetype=vmstat
| bucket _time span=5m
| multikv fields
| stats avg(memUsedPct) as MemoryUsed by host

Rohit Joshi
Splunk Architect

View solution in original post

0 Karma

rohit1793
SplunkTrust
SplunkTrust

There is a command multikv, it works for tabled data like we get from Unix/Linux machines:

index=foo host=abc* sourcetype=vmstat
| bucket _time span=5m
| multikv fields
| stats avg(memUsedPct) as MemoryUsed by host

Rohit Joshi
Splunk Architect
0 Karma

rmmiller
Contributor

Are you looking for help interpreting the data, i.e., what each numerical field represents? Or are you looking for help with parsing into individual fields?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...