i have a index and sourcetype
index=mmts-app sourcetype=application:logs how do i get a CPU and memory for this query.
Does your data in Splunk contain CPU and memory information, if so, what does the data look and what fields do you currently have extracted and visible as fields?
You need to provide more information for someone to be able to help. I am guessing that you want to find CPU and memory information from the data relating to that query, but the question could also be read as what CPU and memory are consumed when you are running the query.