thanks @PickleRick for helping out here. According to the suggestion you provide below I constructed the following query shown below. However, I need to fulfill below requirements, please let me know. Q1: - How can I verify this by the host. Q2: - head 6 (each time it should check for a 5-minute range event)? Q3:- Can we able to display the results of those last 5 intervals cpu percentage values in a new column ? ex:- 86, 92, 89,45,99,90 index=* sourcetype=cpu host=* earliest=-35m | rename "%_Idle_Time" as Percent_Idle_Time | eval CpuUsage=coalesce(100-Percent_Idle_Time,100-PercentIdleTime) | head 6 | stats count(eval(CpuUsage > 85)) as count | eval result=if(count>=5,"High utilization","Normal")
... View more