Getting Data In

How to exclude or filter 0% window process from hostmetrics - process?

fongpen
Path Finder

Hi Guru, 

How do we exclude 0% process usage from Hostmetrics? We would like to capture those process have >0% usage only..

Appreciate if you can provide the sample. 

hostmetrics:
collection_interval: 10s
scrapers:
# System processes metrics, disabled by default
process:    (filter / exclude 0% process usage)

0 Karma
1 Solution

fongpen
Path Finder

fongpen_0-1666776435680.png

Replied from Splunk Support :  unfortunately, it looks like it's not possible to exclude process metrics which have 0% value

View solution in original post

0 Karma

fongpen
Path Finder

fongpen_0-1666776435680.png

Replied from Splunk Support :  unfortunately, it looks like it's not possible to exclude process metrics which have 0% value

0 Karma

fongpen
Path Finder

Samples: -

Include : * Process > 0% 

Process more than 0 percent.JPG

 

Exclude : * Process = 0% 

Process 0 percent.JPG

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

These appear to be screenshots - Splunk doesn't ingest these very well.

0 Karma

fongpen
Path Finder

I would like to have something like this:-

PS > Get-Counter '\Process(*)\% Processor Time' -ErrorAction SilentlyContinue | Select-Object -ExpandProperty CounterSamples | Sort-Object -Property cookedvalue -Descending | Where-Object CookedValue -gt 0

 

*** There are thousand of 0% process which wasted a lot of space and custom metrics license. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample raw events that you are trying to ingest, both the ones you want to keep and the one you want to exclude.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you provide some sanitised events  so we can see what you are dealing with?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...