Splunk search for CPU usage over time on Linux machine
Copy
sourcetype=top pctCPU=* | timechart sum(pctCPU) as pctCPU by host
This search will provide the % of CPU used by host over time. This depends on the top sourcetype which can be obtained using the Add on for Unix/Linux