I've put together some SWQL and have been querying that via Splunk to extract interface stats but I'm not getting the expected results.
My query is:
SELECT I.Node.Caption, I.IfName,
Avg(I.Traffic.OutAveragebps) AS [Avg Tx bps],
MAX(I.Traffic.OutMaxbps) AS [Max Tx bps],
MIN(I.Traffic.OutMinbps) AS [Min Tx bps],
Avg(I.Traffic.InAveragebps) AS [Avg Rx bps],
MAX(I.Traffic.InMaxbps) AS [Max Rx bps],
MIN(I.Traffic.InMinbps) AS [Min Rx bps]
FROM Orion.NPM.Interfaces I
WHERE (I.Node.Caption LIKE 'RT-%') AND (I.IfName Like 'Port-Ch%')
GROUP BY I.Node.Caption, I.IfName
And I'm getting data into Splunk, however it does't look as I expect.
Adding the RX+TX to get a basic throughput figure, I'd expect something like:
But what I'm actually getting is:
Is there something wrong with my query, or is the data returned normalized over a period of time rather than a real-time figure the interface was observing?
Any ideas how I can get real-time (or last polled) data?
Thank you
Glen.