Splunk IT Service Intelligence

Graph of multiple metric_names

Explorer

I have about 100 different metrics_names and I'd like to be able to

  1. Get the metric_name
  2. Plot that metric_name over time

I have about 100 hosts and they all have a metric racknumber and serialnumber.

The 100 hosts I don't care about but I want to plot every single metric where racknumber=1 and serialnumber=12345 and take a look at it.

Labels (2)
0 Karma

Explorer

I think I may have answered my own question

|mstats avg(value) as latestvalue span=15m WHERE metricname=* index=* racknumber=1 serialnumber=12345 by metricname
|where latestvalue > 10000
|timechart span=15m avg(latest
value) by metric_name limit=0

0 Karma