Splunk Search

Help me with splunk query to monitor CPU and Memory utilized by splunk adhoc and alert searches

cogh3o
New Member

Help me with splunk query to monitor CPU and Memory utilized by splunk adhoc and alert searches

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

@cogh3o As you are new to this forum, you may not know that "Splunk" is not a purpose made application.  No one here knows what your data looks like.  To ask an answerable question, follow these golden rules; nay, call them the four commandments:

  • Illustrate data input (in raw text, anonymize as needed), whether they are raw events or output from a search (SPL that volunteers here do not have to look at).
  • Illustrate the desired output from illustrated data.
  • Explain the logic between illustrated data and desired output without SPL.
  • If you also illustrate attempted SPL, illustrate actual output and compare with desired output, explain why they look different to you if that is not painfully obvious.
0 Karma

akkoem
Explorer

Are you looking for general metrics/usage or metrics per search/alert ? 

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...