Splunk Search

Calculate a % based on two Windows Perfmon Counters

chrismor
Explorer

I am trying to calculate the percentage usage of disk from an application based on it's perfmon counters. Unfortunately it doesn't give me this value as a counter. I have "Data File Size" and "Data File Space Used". But as a newbie, how to do take the Value fields into something I can use?

Thanks!

Tags (1)
0 Karma

cphair
Builder

I can't tell from the counter names what the difference is between them, so my formula may be off, but I got something like the following to work:

index=perfmon counter="Data File Size" | stats avg(Value) as Avg1 by host | join host [search index=perfmon counter="Data File Space Used" | stats avg(Value) as Avg2 by host] | eval Ratio=Avg1/Avg2 | fields host,Ratio

I feel like there should be a solution that doesn't run a join, but if your data isn't too extensive this might work. Let me know if that helps.

http://docs.splunk.com/Documentation/Splunk/4.3.1/SearchReference/Eval

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...