Splunk Search

How to combine WinHostMon and Perfmon data to get CPU usage per MSSQL server instance?

kamgineer
Explorer

The goal here is to get CPU usage per SQL instance. As far as I can tell there is no perfmon counter that will give you this data-- please correct me if I'm wrong.

So the only way I can figure to get this is combining WinHostMon data with Perfmon data.

WinHostMon data looks like this:

Type=Service
Name="MSSQL$SYSTEMS2"
DisplayName="SQL Server (SYSTEMS2)"
Description="Provides storage, processing and controlled access of data, and rapid transaction processing."
Path=""C:\Program Files\Microsoft SQL Server\MSSQL11.SYSTEMS2\MSSQL\Binn\sqlservr.exe" -sSYSTEMS2"
ServiceType="Own Process"
StartMode="Manual"
Started=true
State="Running"
Status="OK"
ProcessId=7880

and the PerfMon data looks like this (in 2 separate, unrelated events)

Event1:

12/20/2016 16:50:43.866 -0500
collection=sqlserverhost:process
object=Process
counter="ID Process"
instance=sqlservr
Value=7880

Event2:

12/20/2016 16:50:43.866 -0500
collection=sqlserverhost:process
object=Process
counter="% Processor Time"
instance=sqlservr
Value=3.1103384864426066869

Any idea how to combine all three of these events into 1 event and get a result that looks like:
DisplayName,ProcessID,%CPU

eg:

"SQL Server (SYSTEMS2)", 7880, 3.11 
0 Karma

rahulsaxena015
New Member

You may need to join your search query to manipulate the results

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...