Getting Data In

How to display latest Linux os values grouped by hosts

zoveress
Engager

I need to display the latest cpu, memory, etc information grouped by host in a table format. I have managed to pull cpu or memory individually or if I use stats it will only display the latest value which isn't grouped by host. My initial search which lists the CPU load by host is:

host=* index="linuxos" CPU=all  | dedup host | rename host as name | eval id = "urn:host:/".name  , type="vm", tags=id, identifiers=id | table id type name tags identifiers cpu_load_percent

I need to expand this to memory and possibly even more os related information.

1 Solution

woodcock
Esteemed Legend

Like this:

index="linuxos" AND CPU="all"
| fields host id type tags identifiers cpu_load_percent and other metrics fields here
| stats latest(*) AS * BY host

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

index="linuxos" AND CPU="all"
| fields host id type tags identifiers cpu_load_percent and other metrics fields here
| stats latest(*) AS * BY host
0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...