Splunk Enterprise

help on subsearch with strange behaviour

jip31
Motivator

hi

the search below returns results

 

 

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| join host 
    [ search index=tutu sourcetype=toto
    | fields type host cpu_core) 
    | stats max(cpu_core) as nbcore by host ] 
| eval Vel = (runq / nbcore) / 6

 

 

 but when I add 

 

 

table vel

 

 

or

 

 

| stats avg(Vel) as Vel

 

 

at the end of the search, there is no results

what is wrong please?

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you are just trying to find the maximum number of cpu_core for each host, so you could try eventstats:

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| eventstats max(cpu_core) as nbcore by host
| eval Vel = (runq / nbcore) / 6

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you are just trying to find the maximum number of cpu_core for each host, so you could try eventstats:

index=tutu sourcetype=toto runq 
| search NOT runq=0.0 
| table runq host 
| eventstats max(cpu_core) as nbcore by host
| eval Vel = (runq / nbcore) / 6
0 Karma

jip31
Motivator

I found, a sysntex error in eval...

0 Karma

jip31
Motivator

you search is doing the same thing

and what I need is to be able to do an average on the field "Vel" ( | stats perc(Vel))

so as long as there is no results with | table Vel, I can't doing this average

How explain that I am not able to retrieve the field "Vel"?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...