Splunk Search

How to perform a division between subresults

rootto
Explorer

Hi all,

I would like to perform the following

each result returned by

source="wmi:cputime" daysago=30 | where PercentProcessorTime>=80 | stats count by host

divided by each result retuned by

source="wmi:cputime" daysago=30 | where PercentProcessorTime>=0 | stats count by host

I need this result in order to get the monthly usage of the resource per host. And idea? Cheers

Nicola

Tags (1)
0 Karma

rootto
Explorer

I found the answer to my own question:

source="wmi:cputime" daysago=30 | stats count(eval(PercentProcessorTime>=80)) as Total_80, count(eval(PercentProcessorTime)) as Total by host| eval percentage=(Total_80/Total)*100

sideview
SplunkTrust
SplunkTrust

Note: a slightly simpler search would be just:

source="wmi:cputime" | stats count count(eval(PercentProcessorTime>=80)) as Total_80 by host| eval percentage=(Total_80/count)*100

0 Karma

jrodman
Splunk Employee
Splunk Employee

It seems like the question here is: for events with a PercentProcessorTime field, what quantity are 80 or more? If wrong, maybe a rephrase of the question might clarify.

Try something like: source="wmi:cputime" daysago=30 PercentProcessorTime=* | eval cpu_business=if(PercentProcessorTime>=80, "busy", "not_so_busy") | stats count by host, cpu_business

0 Karma

rootto
Explorer

Hi jrodman,

thanks for the answer. What I'm looking for is the amount of time the cpu was over 805 in the last months.

So if th first query returns:

Host1 3577
Host2 312

and the second:
Host1 63112
Host2 32125

I would like to write a single query to get:
Host1 5.66%
Host2 0.97%

Probably there is an easier way of getting the result, but at the moment I'm not getting it. any suggestions?
Thanks Nicola

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...