Monitoring Splunk

Re: How can I check the CPU utilization of the SH / indexer from the search?


Hi @damucka

Try running this query:

(component=Hostwide host=splunkitsi index=_introspection sourcetype=splunk_resource_usage) 
| eval cpu = 100 - 'data.cpu_idle_pct'
| timechart Median(cpu) AS "cpu" by host

There are plenty of good searches in the monitoring console you can use to try figure out why performance is bad.

All the best.

Labels (3)


Hi @chrisyoungerjds

Just simple search index=_introspection does not bring back any result for me. Would that mean I have no authorization for it? Or is it coming first with the ITSI product, which we do not have?

Kind Regards,

0 Karma


No its not ITSI. You will need to be a Splunk admin role to see it.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...