Splunk Search

Calculate time server CPU above alert percentage

timrich66
Path Finder

Hi,

I need to track the number of times and duration where the CPU used percent is above a threshold number.

The search below shows a server that exceeds the threshold for 3 periods over the last 3 days.  What I want to get is a result that shows me the number of times the threshold has been exceeded and for how long.

timrich66_0-1627654342975.png

I have tried using 'streamstats' and 'bin' but am not entirely sure how to achieve my goal.

Thanks

Labels (1)
0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.