Hi @damucka
Try running this query:
(component=Hostwide host=splunkitsi index=_introspection sourcetype=splunk_resource_usage)
| eval cpu = 100 - 'data.cpu_idle_pct'
| timechart Median(cpu) AS "cpu" by host
There are plenty of good searches in the monitoring console you can use to try figure out why performance is bad.
All the best.
Hi @chrisyoungerjds
Just simple search index=_introspection does not bring back any result for me. Would that mean I have no authorization for it? Or is it coming first with the ITSI product, which we do not have?
Kind Regards,
Kamil
No its not ITSI. You will need to be a Splunk admin
role to see it.