I am using this query to get the Percentage CPU Utilization.
index=os sourcetype="cpu" minutesago=15 | eval human_readable_time=strftime(_time, "%Y-%d-%m %H:%M:%S") |
table host, human_readable_time, pctUser, pctIdle
It work fine on Splunk 4.5 version but i am not getting data on 4.2.3 version, i am not getting data for pctUser and pctIdle fields
Kindly Help
He meant Splunk for Unix/Linux app v4.5
It is working fine.
Thanks,
Rajiv
great! then if you could accept the answer it will be useful for other with same issue.
i used the following to get it to work on 4.5:
index=os sourcetype="cpu" minutesago=15 | multikv forceheader=1 | eval human_readable_time=strftime(_time, "%Y-%d-%m %H:%M:%S") | table host, human_readable_time, pctUser, pctIdle
Which version of Splunk are you running? 4.3.1 is the latest.