Splunk Search

Combining results in metric index?

winknotes
Path Finder

I have a metric index with a hierarchical structure (maybe all metric indexes are like this).  
SuperCategory.Category1.metric1
                                                  .metric2
                                                  .metric3
SuperCategory.Category2.metric1
                                                      .metric2

There is a many to one relationship between categories.  I've tried many different combination methods but my starting point was:

 

 

 

|  mstats  avg(Vmax.StorageGroup.HostIOs) as IOPs avg(Vmax.StorageGroup.AllocatedCapacity) as SgCapacity avg(Vmax.Array.UsableCapacity) as ArrayCap avg(Vmax.Array.HostIOs) as ArrayIOPS 
WHERE index=storage_metrics by Array_Name, Loc, sgname span=1d 
| eval SgIOPs = round(IOPs, 2), SgCapacity = round(SgCapacity, 2), SgCapPct=round((SgCapacity/ArrayCap)*100, 2), SgIOPct=round((IOPs/ArrayIOPS)*100, 2)
| table sgname Array_Name Loc SgIOPs ArrayIOPS SgIOPct SgCapacity ArrayCap SgCapPct  _time

 

 

 

Nothing is returned for any of the Vmax.Array metrics.  There are many 'sgname' to any single 'Array_Name'.  As you can probably tell I'm trying to calculate what % of an array total an sgname is using.  I find myself in this situation quite often and don't really know how to handle it.  

I appreciate any help anyone can offer.   

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...