Splunk Enterprise

help on subsearch with strange behaviour

jip31
Motivator

hi

the search below returns results

 

 

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| join host 
    [ search index=tutu sourcetype=toto
    | fields type host cpu_core) 
    | stats max(cpu_core) as nbcore by host ] 
| eval Vel = (runq / nbcore) / 6

 

 

 but when I add 

 

 

table vel

 

 

or

 

 

| stats avg(Vel) as Vel

 

 

at the end of the search, there is no results

what is wrong please?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you are just trying to find the maximum number of cpu_core for each host, so you could try eventstats:

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| eventstats max(cpu_core) as nbcore by host
| eval Vel = (runq / nbcore) / 6

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you are just trying to find the maximum number of cpu_core for each host, so you could try eventstats:

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| eventstats max(cpu_core) as nbcore by host
| eval Vel = (runq / nbcore) / 6
0 Karma

jip31
Motivator

I found, a sysntex error in eval...

0 Karma

jip31
Motivator

you search is doing the same thing

and what I need is to be able to do an average on the field "Vel" ( | stats perc(Vel))

so as long as there is no results with | table Vel, I can't doing this average

How explain that I am not able to retrieve the field "Vel"?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...