Advertisement
Guest User

Usefull Search

a guest
Dec 22nd, 2014
169
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1. sourcetype=splunk_resource_usage component=PerProcess
  2. | eval process = 'data.process'
  3. | eval args = 'data.args'
  4. | eval sid = 'data.search_props.sid'
  5. | eval process_class = case( process=="mongod","KV store", process=="splunk-optimize","index service", process=="sh" OR process=="ksh" OR process=="bash" OR like(process,"python%") OR process=="powershell","scripted input")
  6. | eval process_class = case( process=="splunkd" AND ((like(args,"-p %start%") AND NOT like(args,"%process-runner%")) OR args=="service"),"splunkd server", process=="splunkd" AND isnotnull(sid),"search", process=="splunkd" AND (like(args,"fsck%") OR like(args,"recover-metadata%") OR like(args,"cluster_thing")),"index service", process=="splunkd" AND args=="instrument-resource-usage", "scripted input", (like(process,"python%") AND like(args,"%/appserver/mrsparkle/root.py%")) OR like(process,"splunkweb"),"Splunk Web", isnotnull(process_class), process_class)
  7. | eval process_class = if(isnull(process_class),"other",process_class)
  8. | search process_class=search
  9. | stats latest(data.mem_used) as memoryused by data.pid,data.search_props.sid,data.search_props.type
  10. | sort -memoryused
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement