Skip to content

Instantly share code, notes, and snippets.

Created January 22, 2016 16:13
Show Gist options
  • Save anonymous/ff9168779cc55d843ae7 to your computer and use it in GitHub Desktop.
Save anonymous/ff9168779cc55d843ae7 to your computer and use it in GitHub Desktop.
Search query for search memory usage
index=_introspection sourcetype=splunk_resource_usage component=PerProcess | eval process = 'data.process' | eval args = 'data.args' | eval sid = 'data.search_props.sid' | eval process_class = case( process=="mongod","KV store", process=="splunk-optimize","index service", process=="sh" OR process=="ksh" OR process=="bash" OR like(process,"python%") OR process=="powershell","scripted input") | eval process_class = case( process=="splunkd" AND ((like(args,"-p %start%") AND NOT like(args,"%process-runner%")) OR args=="service"),"splunkd server", process=="splunkd" AND isnotnull(sid),"search", process=="splunkd" AND (like(args,"fsck%") OR like(args,"recover-metadata%") OR like(args,"cluster_thing")),"index service", process=="splunkd" AND args=="instrument-resource-usage", "scripted input", (like(process,"python%") AND like(args,"%/appserver/mrsparkle/root.py%")) OR like(process,"splunkweb"),"Splunk Web", isnotnull(process_class), process_class) | eval process_class = if(isnull(process_class),"other",process_class) | search process_class=search | stats latest(data.mem_used) as memoryused by data.pid,data.search_props.sid,data.search_props.type | sort -memoryused
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment