Splunk Enterprise

High CPU Utilization Query not working

hotrodbass
Explorer

My SPL code is not returning results.

Here is my SPL:

index=linux sourcetype=cpu
| eval cpu_busy_pct=round(pctUser + pctNice + pctSystem, 2)
| eval cpu_non_idle_pct=round(100 - pctIdle, 2)
| eval high_cpu=if(cpu_busy_pct >= 90, 1, 0)
| where high_cpu=1
| table _time host pctUser pctNice pctSystem pctIowait pctIdle cpu_busy_pct cpu_non_idle_pct

####

I'm dissecting the SPL code:

cpu_busy_pc = pctUser (99.50) + pctNice (.25) + pctSystem (0)

cpu_non_idle_pct = (100 - 0)

cpu_non_idle_pct = 100

the line of code is 

if(cpu_busy_pct >= 90, 1, 0)

My cpu_busy_pct is greater than 90, it's 99.75

But it is not displaying

It will display if the SPL is only:

index=linux sourcetype=cpu

Guidance please.

 

 

 

Labels (1)

PickleRick
SplunkTrust
SplunkTrust

Your SPL is quite straightforward so either:

1. The fields you're trying to use are not extracted and you're trying to use fields which aren't there. Or

2. The fields are ther but aren't numerical. The usual case is when they are multivalued

hotrodbass
Explorer

You are correct! I had to use the following code below to extract the fields.

rex field=_raw "(?<pctUser>[0-9]+(?:\.[0-9]+)?)\s+(?<pctNice>[0-9]+(?:\.[0-9]+)?)\s+(?<pctSystem>[0-9]+(?:\.[0-9]+)?)\s+(?<pctIowait>[0-9]+(?:\.[0-9]+)?)\s+(?<pctIdle>[0-9]+(?:\.[0-9]+)?)"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...