Splunk Enterprise

How to find maximum value

Azwaliyana
Path Finder

I want to display the maixmum percentage and the mounted but I do not know the command.
because the file is not in csv. It is a txt file and I use multikv to extract the field.

Azwaliyana_0-1638934692835.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| multikv forceheader=2
| eval Use_ = rtrim(Use_,"%")
| chart max(Use_) by Mounted

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you give an example of the data you have

 

0 Karma

Azwaliyana
Path Finder

@bowesmana I have replied above

0 Karma

Azwaliyana
Path Finder

Azwaliyana_0-1638946632122.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please can you share as text in a code block </> rather than an  image?

0 Karma

Azwaliyana
Path Finder

 

fs-3 | CHANGED | rc=0 >>
Filesystem                                                 Size  Used Avail Use% Mounted on
devtmpfs                                                    16G  4.0K   16G   1% /dev
tmpfs                                                       16G   16K   16G   1% /dev/shm
tmpfs                                                       16G  1.6G   15G  10% /run
tmpfs                                                       16G     0   16G   0% /sys/fs/cgroup
/dev/mapper/rhgs-root                                       23G  8.3G   15G  37% /
/dev/vda1                                                 1014M   91M  924M   9% /boot

@ITWhisperer @bowesmana 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| multikv forceheader=2
| eval Use_ = rtrim(Use_,"%")
| chart max(Use_) by Mounted
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...