Splunk Search

Calculate time server CPU above alert percentage

timrich66
Communicator

Hi,

I need to track the number of times and duration where the CPU used percent is above a threshold number.

The search below shows a server that exceeds the threshold for 3 periods over the last 3 days.  What I want to get is a result that shows me the number of times the threshold has been exceeded and for how long.

timrich66_0-1627654342975.png

I have tried using 'streamstats' and 'bin' but am not entirely sure how to achieve my goal.

Thanks

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...