Splunk Search

free vs. used visualization ideas?

Justin_Grant
Contributor

I'd like to chart free memory vs. used memory over time on the same Splunk dashboard module. I'm trying to figure out a good visualization to use.

This sounds like a pretty common charting use-case. Splunk experts: how have you visualized free vs. used metrics in your own reports, and what Splunk commands did you use to create that visualization?

Tags (1)

Stephen_Sorkin
Splunk Employee
Splunk Employee

I typically use a stacked area or column chart to represent free vs. used quantities. This is because together the free+used should equal the total in the system. Of course, in some metrics, the OS itself will take a slice that's either unreported or reported as buffers/cached. If you want to preserve the relative usage regardless of system usage, you can switch from an ordinary stacked chart to a 100% stacked chart.

Assuming that you have two fields in your time-series data, one for free and one for used, you can just use timechart: ... | timechart median(free) median(used). If you want to look at extremal behavior, use min(free) and max(used).

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...