Splunk Search

Search query for permon counter

rsathish47
Contributor

Hi All,

we had configured splunk to get the perfmon counter data from server (every 5mins). The counter value gets reset frequently.

We found that raw data is not coming in the Order (time sorted). And some time the counter value is getting incremented with in second as shown below. we cann't use sort . it limits for 10,000 (as per standard conf). we are receiving more then 10 lak events per day in perfmon

data is comes like below per sec

Date Server counter Value

09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3932     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3929     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3937

Expected :

We are expecting as below.

Date Server counter Value

09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3937     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3932     
09_29_2014_00_47_36 WTPCPJLKVS69 Messages Processed 3929

We are using Stream stats to calculate the total capture message per day.

Query:

index=win_srv_perf (object="XXXXXXXXXXX") counter="XXXXXXXXXX" host="XXXXXXXXXX"| eval Time = strftime(_time,"%m_%d_%Y_%H_%M_%S") | streamstats current=f last(Value) as newValue by host counter | eval msgDiff=(if(newValue>=Value,newValue-Value,newValue)) | table Time DumID host counter Value newValue msgDiff | stats sum(msgDiff) as value by host counter
Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

You can use "|sort 0 host, counter, Value" to sort more than 10000 rows.

View solution in original post

somesoni2
Revered Legend

You can use "|sort 0 host, counter, Value" to sort more than 10000 rows.

rsathish47
Contributor

Thanks Somesoni2.. It worked

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...