<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to plot a delta timechart of average response time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366794#M108202</link>
    <description>&lt;P&gt;Thanks for the quick response but can you please provide computing the delta part of it?&lt;/P&gt;</description>
    <pubDate>Sat, 18 Mar 2017 09:39:53 GMT</pubDate>
    <dc:creator>gokadroid</dc:creator>
    <dc:date>2017-03-18T09:39:53Z</dc:date>
    <item>
      <title>How to plot a delta timechart of average response time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366792#M108200</link>
      <description>&lt;P&gt;I have data like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;timestamp, serviceName, responseTime(in ms)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I want to plot the &lt;CODE&gt;per minute delta of avg. responseTime (difference between avg responseTime yesterday vs today) by serviceName&lt;/CODE&gt;. Average is taken every minute. I want to observe only half an hour window.&lt;/P&gt;

&lt;P&gt;Sample data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03/17/2017 00:00:01 service1 242 
03/17/2017 00:00:02 service2 300
03/17/2017 00:00:03 service3 350 
03/17/2017 00:00:04 service1 280 
03/17/2017 00:00:05 service2 290 
03/17/2017 00:00:06 service3 300 
:
:
03/18/2017 00:00:01 service1 1242 
03/18/2017 00:00:02 service2 1300
03/18/2017 00:00:03 service3 1350 
03/18/2017 00:00:04 service1 1280 
03/18/2017 00:00:05 service2 1290 
03/18/2017 00:00:06 service3 1300 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;- The avg(ResponseTime) of service1 for 03/17/2017 00:00 is (242+280)/2 = 261ms
- The avg(ResponseTime) of service1 for 03/18/2017 00:00 is (1242+1280)/2 = 1261ms
- Hence the delta avg(RespTime) for service 1 at 00:00 between yesterday and today is 1261-261 = 1000ms. It might also be negative 1000 if it was 1261 yesterday and 261 today.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I want to plot this delta by service name on a timechart for a window of last 30 minutes from now only.  Please assist.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;NOTE&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;- Services are more than three
- One service might get called mote than other service within a minute. So service1 might get called multiple times within a minute while chances are service2 might not be called at all within that minute.
- There is no sequence in which services are called (sample data makes it look like service1, 2 and 3 are in sequence)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 18 Mar 2017 09:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366792#M108200</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2017-03-18T09:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to plot a delta timechart of average response time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366793#M108201</link>
      <description>&lt;P&gt;Hi gokadroid,&lt;BR /&gt;
see timewrap command (&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Timewrap"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Timewrap&lt;/A&gt;)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your_search 
| timechart avg(responsetime) AS responsetime count span=min 
| timewrap 1d align=now 
| sort -_time 
| head 30 
| eval diff=responsetime_latest_day-responsetime_1day_before
| table _time responsetime_latest_day responsetime_1day_before diff
| rename responsetime_latest_day AS Today responsetime_1day_before AS Yesterday diff AS Difference
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Using 2 days as time period&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2017 09:32:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366793#M108201</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-03-18T09:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to plot a delta timechart of average response time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366794#M108202</link>
      <description>&lt;P&gt;Thanks for the quick response but can you please provide computing the delta part of it?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2017 09:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366794#M108202</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2017-03-18T09:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to plot a delta timechart of average response time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366795#M108203</link>
      <description>&lt;P&gt;Here is a run anywhere example (you will swap your base search and &lt;CODE&gt;host&lt;/CODE&gt; for &lt;CODE&gt;service&lt;/CODE&gt; and &lt;CODE&gt;1h&lt;/CODE&gt; for &lt;CODE&gt;1m&lt;/CODE&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_introspection sourcetype=splunk_resource_usage 
| timechart span=1h avg(data.reads_kb_ps) AS HourlyAvgResponseTime BY host
| untable _time host HourlyAvgResponseTime
| eval hourmin=strftime(_time, "%H:%M")
| reverse
| streamstats current=f last(HourlyAvgResponseTime) AS prevHourlyAvgResponseTime BY hourmin host
| reverse
| eval delta=HourlyAvgResponseTime-prevHourlyAvgResponseTime
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 18 Mar 2017 16:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-plot-a-delta-timechart-of-average-response-time/m-p/366795#M108203</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-18T16:06:31Z</dc:date>
    </item>
  </channel>
</rss>

