Splunk Enterprise

How to find maximum value

Azwaliyana
Path Finder

I want to display the maixmum percentage and the mounted but I do not know the command.
because the file is not in csv. It is a txt file and I use multikv to extract the field.

Azwaliyana_0-1638934692835.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| multikv forceheader=2
| eval Use_ = rtrim(Use_,"%")
| chart max(Use_) by Mounted

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you give an example of the data you have

 

0 Karma

Azwaliyana
Path Finder

@bowesmana I have replied above

0 Karma

Azwaliyana
Path Finder

Azwaliyana_0-1638946632122.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share as text in a code block </> rather than an  image?

0 Karma

Azwaliyana
Path Finder

 

fs-3 | CHANGED | rc=0 >>
Filesystem                                                 Size  Used Avail Use% Mounted on
devtmpfs                                                    16G  4.0K   16G   1% /dev
tmpfs                                                       16G   16K   16G   1% /dev/shm
tmpfs                                                       16G  1.6G   15G  10% /run
tmpfs                                                       16G     0   16G   0% /sys/fs/cgroup
/dev/mapper/rhgs-root                                       23G  8.3G   15G  37% /
/dev/vda1                                                 1014M   91M  924M   9% /boot

@ITWhisperer @bowesmana 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| multikv forceheader=2
| eval Use_ = rtrim(Use_,"%")
| chart max(Use_) by Mounted
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...