Splunk Search

How do you compare the average memory performance of 2 servers?

mboiz
New Member

Hi All,

Please help me create a query that compares cpu and memory with threshold performance in 1 month ( 4 data ) in 2 diff servers with a preview below

alt text

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

You didn't provide any of your search so this is a lot harder. But hopefully...

index=blah host=HostA OR host=HostB
| eval MyThreshold=.8
| timechart avg(CPU_Percent) AS CPU, avg(MEM_Percent) AS Memory avg(MyThreshold) AS Threshold BY host

If you wanted extra fanciness, you could also use perc95(CPU_Percent) to get the 95th percentile, or max(), or ... any of the other statistical and charting functions.

Happy Splunking,
Rich

Richfez
SplunkTrust
SplunkTrust

Has this answer helped you solve your problem? If so, please "Accept" it so the next person stumbling across it in a search will know that this worked.

If this is still unresolved, please provide more information on what's not working.

If this is resolved and you've found another answer - great! Post that here as an answer, and go ahead and mark it as Accepted! It's OK to gather karma for yourself occasionally like that.

0 Karma

mboiz
New Member

Thank you rich,

that way is i want, but why the result is only threshold ? no avg preview
i want to create 2 data memory & cpu from 2 servers with result above

Thanks

0 Karma

Richfez
SplunkTrust
SplunkTrust

The result is only threshold probably because you didn't provide me with any information about your fields. So I made up names, like "CPU_Percent". You have to fill those in because I don't know what they are.

Your question and answers haven't made one thing clear - where are you at in this endeavor? Do you have Splunk installed, are you collecting performance metrics or CPU stats or whatever you need already?

0 Karma

mboiz
New Member

here my query

host="121" OR host="122" sourcetype="cpu"

| timechart eval(round(avg(PercentUserTime),0)."%") span=w by host
| eval threshold=90

but graph cant appear likes on attachment

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...