Security

how to find out the maximum CPU percentage the host reached for last one month

ksarode
Explorer

i want to find out the maximum CPU utilization reached by the server "xyz" in last one month

Tags (1)
0 Karma

xpac
SplunkTrust
SplunkTrust

You only provided little detail, so you'll have to adapt this to your data:

index=yourindex sourcetype=yoursourcetype
| timechart span=1mon max(yourfield) by host

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

0 Karma

FrankVl
Ultra Champion

Since he is looking for max in last month, a simple | stats max(yourfield) by host would do right (and then use the timepicker to run that over the desired timerange)?

xpac
SplunkTrust
SplunkTrust

Yeah, I thought it might be useful to have a comparison handy, but that might actually be enough 😉

0 Karma

xpac
SplunkTrust
SplunkTrust

Please add some details: Do you already have that data? Is it Windows, Linux.... like, basics. 😉

0 Karma

ksarode
Explorer

its an unix box and also these servers are getting monitored in splunk and also CPU,memory,disk is getting monitored to trigger an alert of it is crossing 70%

0 Karma

ksarode
Explorer

but here they want to see the maximum range host has reached in last month

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...