Splunk Search

Calculate a % based on two Windows Perfmon Counters

chrismor
Explorer

I am trying to calculate the percentage usage of disk from an application based on it's perfmon counters. Unfortunately it doesn't give me this value as a counter. I have "Data File Size" and "Data File Space Used". But as a newbie, how to do take the Value fields into something I can use?

Thanks!

Tags (1)
0 Karma

cphair
Builder

I can't tell from the counter names what the difference is between them, so my formula may be off, but I got something like the following to work:

index=perfmon counter="Data File Size" | stats avg(Value) as Avg1 by host | join host [search index=perfmon counter="Data File Space Used" | stats avg(Value) as Avg2 by host] | eval Ratio=Avg1/Avg2 | fields host,Ratio

I feel like there should be a solution that doesn't run a join, but if your data isn't too extensive this might work. Let me know if that helps.

http://docs.splunk.com/Documentation/Splunk/4.3.1/SearchReference/Eval

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...