Thank you that worked well. The only big issue I see, which is to still be tested. I had created a search that updated every min within Splunk, but when I set the URL, it appears it wants a different schedule.
index=main sourcetype=ps host=* earliest=-30s latest=now()
| stats min(_time) as latest by process_name,pid,user,pctCPU
| strcat process_name " - Process: " pctCPU "% Used: " pid " - PID: " user proc
| table proc pctCPU
I just put Host=* so the host I'm using is not avaiable for everyone to see
... View more