index=perfmon eventtype="perfmon_windows" (Host="*") Host="*" object=Process counter="Private_Bytes" earliest=-30m@m latest=-20m@m
| stats avg(Value) AS older by host process_name
| join [search index=perfmon eventtype="perfmon_windows" (Host="*") Host="*" object=Process counter="Private_Bytes" earliest=-20m@m latest=-10m@m | stats avg(Value) AS newer by host process_name _time | convert ctime(_time) as time ] |eval diff= newer - older | eval percent = (diff/older)*100
|table host, process_name, older, newer, percent , time| where newer > 4 * older | sort - percent | outputlookup append=true autotestlookup.csv
this is our current search query to compare the memory and save it in a lookup file. I am not sure if the approach we are trying is the best option.
... View more