Splunk Enterprise

help on subsearch with strange behaviour

jip31
Motivator

hi

the search below returns results

 

 

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| join host 
    [ search index=tutu sourcetype=toto
    | fields type host cpu_core) 
    | stats max(cpu_core) as nbcore by host ] 
| eval Vel = (runq / nbcore) / 6

 

 

 but when I add 

 

 

table vel

 

 

or

 

 

| stats avg(Vel) as Vel

 

 

at the end of the search, there is no results

what is wrong please?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you are just trying to find the maximum number of cpu_core for each host, so you could try eventstats:

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| eventstats max(cpu_core) as nbcore by host
| eval Vel = (runq / nbcore) / 6

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you are just trying to find the maximum number of cpu_core for each host, so you could try eventstats:

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| eventstats max(cpu_core) as nbcore by host
| eval Vel = (runq / nbcore) / 6
0 Karma

jip31
Motivator

I found, a sysntex error in eval...

0 Karma

jip31
Motivator

you search is doing the same thing

and what I need is to be able to do an average on the field "Vel" ( | stats perc(Vel))

so as long as there is no results with | table Vel, I can't doing this average

How explain that I am not able to retrieve the field "Vel"?

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...