sourcetype=top pctCPU=* | timechart sum(pctCPU) as pctCPU by host
0 comments
sourcetype=top pctMEM=* | timechart sum(pctMEM) as pctMEM by host
0 comments
sourcetype=df PercentFreeSpace=* mount="/" | timechart latest(PercentFreeSpace) as "% Free Space" by host
0 comments
sourcetype=cron | rex ".*:\d{2}\s(?<host_name>\S+)" | rex "]:\sfinished(?<info>.*)" | stats count by host_name, info
0 comments
index=_internal sourcetype=scheduler scheduled_time=* savedsearch_name=* | stats count by scheduled_time, savedsearch_name | search count>1 | table savedsearch_name count | rename savedsearch_name as "Search Name" count as "Number of Times This Search Runs Each Time it is Called"
0 comments
|tstats count WHERE index=* OR index=_* by index
0 comments
index=_internal sourcetype=scheduler savedsearch_name=* status=skipped | stats count as Count by savedsearch_name reason | rename savedsearch_name as "Search Name", reason as Reason
0 comments
| tstats count as events BY host,_time,_indextime span=1s | eval indexlag=_indextime-_time | stats avg(indexlag) as "Indexing Lag" by host
0 comments
index=_internal sourcetype=splunkd | stats dc(hostname) as "Unique Splunk Hosts"
0 comments
index=_internal sourcetype=splunkd destPort!="-"| stats count by hostname, sourceHost, host, destPort, version | fields - count | rename hostname as "Forwarder Hostname", sourceHost as "Forwarder IP", host as "Indexer Hostname", destPort as "Forwarding Port", version as "Splunk Version"
0 comments