Splunk Search

Trying to chart process over time unsuccessfully with CPU query

mightaswelby
Explorer

Able to get the expected value running this query, however how would I plot this over time as a timechart?

sourcetype=Script:RunningProc eventtype=Security-proc1 | appendpipe [stats avg(CPUPct) as "CPU %" by Instance] | stats sum(CPU %)

output:
sum(CPU %)
0.156074

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

sourcetype=Script:RunningProc eventtype=Security-proc1
| timechahrt avg(CPUPct) by instance

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this

sourcetype=Script:RunningProc eventtype=Security-proc1
| timechahrt avg(CPUPct) by instance
0 Karma

mightaswelby
Explorer

Thanks for the response somesoni2, however in order to produce the accurate value, the | stats sum(CPU %) needs to be included in the query. (issues with the way windows perfmon passes cpu data). looking to timechart the result sum(CPU % over a period of time and having no luck.

sourcetype=Script:RunningProc eventtype=Security-proc1 | appendpipe [stats avg(CPUPct) as "CPU %" by Instance] | stats sum(CPU %)

output:
sum(CPU %)
0.156074

0 Karma

somesoni2
Revered Legend

How about this? (update span value in bucket command and timechart command per your need)

sourcetype=Script:RunningProc eventtype=Security-proc1 | bucket span=15m _time | stats avg(CPUPct) as "CPU %" by _time instance | timechart span=15m sum("CPU %")  as "CPU %"
0 Karma

mightaswelby
Explorer

This seemed to work perfectly, thank you somesoni2

0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...