Splunk Search

How to make a dashboard which shows systems activity such as percentage usage of processor, memory, disk, etc?

NPR
Path Finder

Hi.

I want to show my system activity inside a dashboard named NPR_my_dashboard_activity.

I want a search which shows the percentage usage of my processor; memory ; disk and network activity.

How can I do it ?
Thank.

0 Karma

stephane_cyrill
Builder

Hi NPR,
To do that you have :

1-Index your local event log or local performance. to do that in splunk web go to SETTING--ADD DATA---MONITOR then select what you want to monitor( processor, memori,system ......)

2- you can create a new index for that.
3- once you have index your machine data,you can now search the index where you put you machine data.
4- build queries using events from that index and save them as Dashboard with title NPR_my_dashboard_activity.

0 Karma

NPR
Path Finder

thank.
but please can you build queries of number 4 ?.
thank.

0 Karma

aweitzman
Motivator

It's difficult to build queries without seeing some sample data. Can you please provide some?

Also, it's not clear what you want the results to be. For instance, you say "memory, disk, and network activity." Do you mean in real time? The last time you polled? An average over the last minute, or hour, or day?

Please read the search documentation and see if you can construct the search yourself first. Please post the searches you tried, what the searches returned, and what results you were looking for.

http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchTutorial/WelcometotheSearchTutorial
http://docs.splunk.com/Documentation/Splunk/6.2.2/Search/Whatsinthismanual

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...