Splunk Search

How to plot max system load against the actual load?

jackpal
Path Finder

I have the following simple query:

index=os sourcetype=vmstat tag=dcv-na | eval MaxLoad = 28  | timechart  max(loadAvg1mi) as LoadAvg,max(MaxLoad) as MaxLoad by host

This works well enough but when multiple hosts are involved its gets busy due to the fact that eval is a plot for each host. I'd like just one line across the chart showing the max value for all hosts. Similar to how the licensing reports work.

0 Karma
1 Solution

somesoni2
Revered Legend

Then lets create the maxLoad line after your time chart like this

index=os sourcetype=vmstat tag=dcv-na  | timechart max(loadAvg1mi) as LoadAvg by host| eval MaxLoad = 28

View solution in original post

0 Karma

jackpal
Path Finder

Some more details are probably in order. In the 30 day license report there is a dotted line for "Stack Size" I would like the max value plot to stand out more.

0 Karma

jackpal
Path Finder

Thanks. Is there a way to label that line on the chart as MaxLoad. I'd like to point on on the chart that this is the maximum.

0 Karma

somesoni2
Revered Legend

Then lets create the maxLoad line after your time chart like this

index=os sourcetype=vmstat tag=dcv-na  | timechart max(loadAvg1mi) as LoadAvg by host| eval MaxLoad = 28
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...