Splunk Search

How to edit my search to find multiple averages from one field based based on the context provided by other fields?

matthewjohnson
Explorer

When working with Windows performance counters, the Value field contains the interesting data for a given context. The context of Value is defined by other fields - the counter field for example.

What I'd like to do is something like this:

index="perfmon" collection="Free Disk Space" | stats avg(Value when counter == "% Free Space") as percent_free avg(Value when counter == "Free Megabytes") as mb_free by host

So I end up with something like this:

Host            | percent_free              | mb_free
--------------------------------------------------------
BigHost1        | 20                        | 3000
BigHost2        | 10                        | 1500
...

How do I accomplish this?

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

index="perfmon" collection="Free Disk Space" counter="% Free Space" OR counter="Free Megabytes" | chart avg(Value) over host by counter | rename "% Free Space" as percent_free "Free Megabytes" as mb_free

View solution in original post

somesoni2
Revered Legend

Try something like this

index="perfmon" collection="Free Disk Space" counter="% Free Space" OR counter="Free Megabytes" | chart avg(Value) over host by counter | rename "% Free Space" as percent_free "Free Megabytes" as mb_free

matthewjohnson
Explorer

Exactly what I wanted - thank you!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...