That is a nice use case.
BTW I hope you are aware that we provide a snapshot of top processes that were running when a threshold is violated or when a server goes down. We send this RCA as an email to the configured user.
I have attached a screenshot of that RCA View here.
We would like to hear any comments you have around that to see how we can make improvements to satisfy your use case too.
In the meantime we will think how we can automagically figure out the top 10 processes that take high CPU and memory across servers over say a fixed unit of time (like every hour).