Getting Data In

How to exclude or filter 0% window process from hostmetrics - process?

fongpen
Path Finder

Hi Guru, 

How do we exclude 0% process usage from Hostmetrics? We would like to capture those process have >0% usage only..

Appreciate if you can provide the sample. 

hostmetrics:
collection_interval: 10s
scrapers:
# System processes metrics, disabled by default
process:    (filter / exclude 0% process usage)

0 Karma
1 Solution

fongpen
Path Finder

fongpen_0-1666776435680.png

Replied from Splunk Support :  unfortunately, it looks like it's not possible to exclude process metrics which have 0% value

View solution in original post

0 Karma

fongpen
Path Finder

fongpen_0-1666776435680.png

Replied from Splunk Support :  unfortunately, it looks like it's not possible to exclude process metrics which have 0% value

0 Karma

fongpen
Path Finder

Samples: -

Include : * Process > 0% 

Process more than 0 percent.JPG

 

Exclude : * Process = 0% 

Process 0 percent.JPG

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

These appear to be screenshots - Splunk doesn't ingest these very well.

0 Karma

fongpen
Path Finder

I would like to have something like this:-

PS > Get-Counter '\Process(*)\% Processor Time' -ErrorAction SilentlyContinue | Select-Object -ExpandProperty CounterSamples | Sort-Object -Property cookedvalue -Descending | Where-Object CookedValue -gt 0

 

*** There are thousand of 0% process which wasted a lot of space and custom metrics license. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample raw events that you are trying to ingest, both the ones you want to keep and the one you want to exclude.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you provide some sanitised events  so we can see what you are dealing with?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...