Splunk search for Memory usage over time on Linux machine
Copy
sourcetype=top pctMEM=* | timechart sum(pctMEM) as pctMEM by host
This search will show memory usage over time separated by host for linux hosts that are reporting to Splunk. This search depends on existence of the 'top' sourcetype which can be incorporated using the Add on for Unix/Linux