I need to personalize the "Data Processing Queues" monitored made by Monitoring Console.
I found that "median" aggregate function, on stats or timechart commands does not work correctly.
Indeed, launching the following search, over "all time" on my PC (host=localhost), I obtain that median is 0 if on values there is a 0.
In the example attached, the correct median is 0.73, instead Splunk calculate 0.
(group=queue host=localhost index=_internal name=* source=*metrics.log sourcetype=splunkd)
| eval ingest_pipe=if(isnotnull(ingest_pipe),ingest_pipe,"none")
| search ingest_pipe=*
| where match(name,"agg")
| eval max=if(isnotnull(max_size_kb),max_size_kb,max_size), curr=if(isnotnull(current_size_kb),current_size_kb,current_size), fill_perc=round(((curr / max) * 100),2)
| timechart minspan=30s Median(fill_perc) values(fill_perc) avg(fill_perc) useother=false limit=15
Anyone else found this issue ?
... View more