Splunk Search

Metrics average

alakdam
Path Finder

Hi,

I am new to splunk metrics search. I am AWS/EBS metrics to splunk. I want to calculate the average throughput and number of IOPS for my Amazon Elastic Block Store (Amazon EBS) volume. I found solutions the solution in AWS: https://repost.aws/knowledge-center/ebs-cloudwatch-metrics-throughput-iops, I don't know how to search it in Splunk. 

This is the max I can do atm 

 

| mpreview index=my-index | search namespace="AWS/EBS" metricName=VolumeReadOps

 

 Really appreciate, if someone help me out, 

Labels (3)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

I assume that my-index is a metrics index.  But still unclear what is being asked.  Generally only you will know what data you get back from AWS/EBS and which metrics are of interest to your use case.   Once you know which metrics you are interested in and what kind of stats (e.g., avg) you want to perform, mstats is your friend.

If you have difficulty figure out which metrics are available, mstats is also your friend:

| mstats count(*) as * where index=my-index ``` my-index must be a metric index ```
| transpose column_name=metric_name

Hope this helps.

View solution in original post

Tags (1)

yuanliu
SplunkTrust
SplunkTrust

I assume that my-index is a metrics index.  But still unclear what is being asked.  Generally only you will know what data you get back from AWS/EBS and which metrics are of interest to your use case.   Once you know which metrics you are interested in and what kind of stats (e.g., avg) you want to perform, mstats is your friend.

If you have difficulty figure out which metrics are available, mstats is also your friend:

| mstats count(*) as * where index=my-index ``` my-index must be a metric index ```
| transpose column_name=metric_name

Hope this helps.

Tags (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...