Splunk Search

How to combine WinHostMon and Perfmon data to get CPU usage per MSSQL server instance?

kamgineer
Explorer

The goal here is to get CPU usage per SQL instance. As far as I can tell there is no perfmon counter that will give you this data-- please correct me if I'm wrong.

So the only way I can figure to get this is combining WinHostMon data with Perfmon data.

WinHostMon data looks like this:

Type=Service
Name="MSSQL$SYSTEMS2"
DisplayName="SQL Server (SYSTEMS2)"
Description="Provides storage, processing and controlled access of data, and rapid transaction processing."
Path=""C:\Program Files\Microsoft SQL Server\MSSQL11.SYSTEMS2\MSSQL\Binn\sqlservr.exe" -sSYSTEMS2"
ServiceType="Own Process"
StartMode="Manual"
Started=true
State="Running"
Status="OK"
ProcessId=7880

and the PerfMon data looks like this (in 2 separate, unrelated events)

Event1:

12/20/2016 16:50:43.866 -0500
collection=sqlserverhost:process
object=Process
counter="ID Process"
instance=sqlservr
Value=7880

Event2:

12/20/2016 16:50:43.866 -0500
collection=sqlserverhost:process
object=Process
counter="% Processor Time"
instance=sqlservr
Value=3.1103384864426066869

Any idea how to combine all three of these events into 1 event and get a result that looks like:
DisplayName,ProcessID,%CPU

eg:

"SQL Server (SYSTEMS2)", 7880, 3.11 
0 Karma

rahulsaxena015
New Member

You may need to join your search query to manipulate the results

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...