Getting Data In

How to exclude or filter 0% window process from hostmetrics - process?

fongpen
Path Finder

Hi Guru, 

How do we exclude 0% process usage from Hostmetrics? We would like to capture those process have >0% usage only..

Appreciate if you can provide the sample. 

hostmetrics:
collection_interval: 10s
scrapers:
# System processes metrics, disabled by default
process:    (filter / exclude 0% process usage)

0 Karma
1 Solution

fongpen
Path Finder

fongpen_0-1666776435680.png

Replied from Splunk Support :  unfortunately, it looks like it's not possible to exclude process metrics which have 0% value

View solution in original post

0 Karma

fongpen
Path Finder

fongpen_0-1666776435680.png

Replied from Splunk Support :  unfortunately, it looks like it's not possible to exclude process metrics which have 0% value

0 Karma

fongpen
Path Finder

Samples: -

Include : * Process > 0% 

Process more than 0 percent.JPG

 

Exclude : * Process = 0% 

Process 0 percent.JPG

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

These appear to be screenshots - Splunk doesn't ingest these very well.

0 Karma

fongpen
Path Finder

I would like to have something like this:-

PS > Get-Counter '\Process(*)\% Processor Time' -ErrorAction SilentlyContinue | Select-Object -ExpandProperty CounterSamples | Sort-Object -Property cookedvalue -Descending | Where-Object CookedValue -gt 0

 

*** There are thousand of 0% process which wasted a lot of space and custom metrics license. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide some sample raw events that you are trying to ingest, both the ones you want to keep and the one you want to exclude.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you provide some sanitised events  so we can see what you are dealing with?

0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...