Hi,
I am collecting some disk performance stats via a Splunk Forwarder from a Windows Server.
I am now trying to graph the disk stats over the last 24 hours using the below.
sourcetype="Perfmon:LocalPhysicalDisk-SQLWEB" host=SQLWEB counter="Avg. Disk sec/Write" | timechart span=3s avg(Value)
I am using a 3s span because i am trying to show more accurate information.
Issue1
When using the 3s span, despite having last 24 hours set, it shows me only the last 20mins. This is really annoying as i am trying to compare the data to another tool, which is able to show me more accurate avergages over 24 hours. If i increase the span, the data becomes less and less accurate in terms of showing "spikes".
Is it possible to have the 3s, or any span, and have Splunk plot the data regardless of plot points, as it seems to be obbeying some kind of rule that dictacts span=x can only ever show x minutes.
Issue2
The data returned is for example 0.013, which is 13ms, is it possible to somehow * 1000, to plot 13, instead of 0.013?
Thanks
Paul
... View more