Getting Data In

How to display latest Linux os values grouped by hosts

zoveress
Engager

I need to display the latest cpu, memory, etc information grouped by host in a table format. I have managed to pull cpu or memory individually or if I use stats it will only display the latest value which isn't grouped by host. My initial search which lists the CPU load by host is:

host=* index="linuxos" CPU=all  | dedup host | rename host as name | eval id = "urn:host:/".name  , type="vm", tags=id, identifiers=id | table id type name tags identifiers cpu_load_percent

I need to expand this to memory and possibly even more os related information.

1 Solution

woodcock
Esteemed Legend

Like this:

index="linuxos" AND CPU="all"
| fields host id type tags identifiers cpu_load_percent and other metrics fields here
| stats latest(*) AS * BY host

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

index="linuxos" AND CPU="all"
| fields host id type tags identifiers cpu_load_percent and other metrics fields here
| stats latest(*) AS * BY host
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...