Splunk Search

Help me with splunk query to monitor CPU and Memory utilized by splunk adhoc and alert searches

cogh3o
New Member

Help me with splunk query to monitor CPU and Memory utilized by splunk adhoc and alert searches

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

@cogh3o As you are new to this forum, you may not know that "Splunk" is not a purpose made application.  No one here knows what your data looks like.  To ask an answerable question, follow these golden rules; nay, call them the four commandments:

  • Illustrate data input (in raw text, anonymize as needed), whether they are raw events or output from a search (SPL that volunteers here do not have to look at).
  • Illustrate the desired output from illustrated data.
  • Explain the logic between illustrated data and desired output without SPL.
  • If you also illustrate attempted SPL, illustrate actual output and compare with desired output, explain why they look different to you if that is not painfully obvious.
0 Karma

akkoem
Explorer

Are you looking for general metrics/usage or metrics per search/alert ? 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...