I wanted to know how we can construct a search query for a service which is running on a centOS server and the utilization has exceeded 70 per cent for last 10 mins ? We are supposed to create an alert if such kind of situation arises? Any help would be greatly appreciated.
Have you considered Splunk Add-on for Unix and Linux from SplunkBase?
@ITWhisperer No I have not considered it.