Splunk Enterprise

High CPU Utilization Query not working

hotrodbass
Explorer

My SPL code is not returning results.

Here is my SPL:

index=linux sourcetype=cpu
| eval cpu_busy_pct=round(pctUser + pctNice + pctSystem, 2)
| eval cpu_non_idle_pct=round(100 - pctIdle, 2)
| eval high_cpu=if(cpu_busy_pct >= 90, 1, 0)
| where high_cpu=1
| table _time host pctUser pctNice pctSystem pctIowait pctIdle cpu_busy_pct cpu_non_idle_pct

####

I'm dissecting the SPL code:

cpu_busy_pc = pctUser (99.50) + pctNice (.25) + pctSystem (0)

cpu_non_idle_pct = (100 - 0)

cpu_non_idle_pct = 100

the line of code is 

if(cpu_busy_pct >= 90, 1, 0)

My cpu_busy_pct is greater than 90, it's 99.75

But it is not displaying

It will display if the SPL is only:

index=linux sourcetype=cpu

Guidance please.

 

 

 

Labels (1)

PickleRick
SplunkTrust
SplunkTrust

Your SPL is quite straightforward so either:

1. The fields you're trying to use are not extracted and you're trying to use fields which aren't there. Or

2. The fields are ther but aren't numerical. The usual case is when they are multivalued

hotrodbass
Explorer

You are correct! I had to use the following code below to extract the fields.

rex field=_raw "(?<pctUser>[0-9]+(?:\.[0-9]+)?)\s+(?<pctNice>[0-9]+(?:\.[0-9]+)?)\s+(?<pctSystem>[0-9]+(?:\.[0-9]+)?)\s+(?<pctIowait>[0-9]+(?:\.[0-9]+)?)\s+(?<pctIdle>[0-9]+(?:\.[0-9]+)?)"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...