How to do it...

Follow these steps to search for the total number of database connections over the past 30 days:

  1. Log in to your Splunk server.
  2. Select the Search & Reporting application.
  3. Ensure that the time range picker is set to Last 7 days and type the following search into the Splunk search bar. Then, click on Search or hit Enter:
index=main sourcetype=log4j perfType="DB" | eval threshold=con_total/100*70 | where con_used>=threshold | timechart span=4h count(con_used) AS CountOverThreshold
  1. Splunk will return a tabulated list, detailing all the events that meet our search criteria, as shown in the following screenshot:
  2. This is great, ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.