Splunk Search

timechart process of cpu usage of maximum PID

indeed_2000
Motivator

Hi
have log like below:
_time                                                source cpu_load_percent process pctCPU cpuTIME   PID
7/14/21 1:59:41.000 PM top          5.6                                     java           5.6          1:49.46     125353

here is my SPL
index="main" pctCPU="*" process="java" pctCPU>0

I have 3 java process that has uniq PID, Now I want to get timechart that show pctCPU of maximum PID.

Any idea?
Thanks

 

Labels (7)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @indeed_2000 

Can you try this?

 

 

index="main" pctCPU="*" process="java" pctCPU>0 
| timechart max(pctCPU) as max_cpu by PID

 

 

 ---

An upvote would be appreciated and Accept Solution if this reply helps!

0 Karma

indeed_2000
Motivator

Thank you for reply, no it's not work, I want maximum PID not pctCPU

I also try this but not work:

index="main" pctCPU="*" process="java" pctCPU>0
| timechart max(PID) as max_cpu by pctCPU

 

FYI: this work on real-time monitoring.

Any idea?

Thanks

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...