Splunk Search

How to create a single chart showing % Processor Time and % User Time by host?

New Member

I'm trying to create a single chart showing % Processor Time and % User Time by host

My example so far:

host="pvawbdap01.ifdsgroup.co.uk" index="bluedoor_registry_perfmon"  source="Perfmon:Processor" | stats avg("% Processor Time") as hRs, avg("% User Time") as ssns by _time,source | eval s1=("% Processor Time % User Time") | makemv s1 | mvexpand s1 | eval yval=case(s1==("% Processor Time"),hRs,s1==("% User Time"),ssns) | eval series=source+":"+s1 | xyseries _time,series,yval
0 Karma

Legend

Would this work?

 host="pvawbdap01.ifdsgroup.co.uk" index="bluedoor_registry_perfmon"
      source="Perfmon:Processor"
 | stats avg("% Processor Time") as hRs, avg("% User Time") as ssns by source
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!