<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to group multiple methods responsetime into intervals and obtain count? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642758#M222625</link>
    <description>&lt;P&gt;This helps. Thank you for the solution!&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2023 04:49:37 GMT</pubDate>
    <dc:creator>Splunk_321</dc:creator>
    <dc:date>2023-05-10T04:49:37Z</dc:date>
    <item>
      <title>How to group multiple methods responsetime into intervals and obtain count?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642624#M222586</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a requirement where I need to group count of methods responsetime into different time intervals.&lt;/P&gt;&lt;P&gt;Below is what I tried&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;basesearch 
| eval ResponseTime=if(uri=="/api/auth",null(),responsetime*1000) 
| rex field=gwrequesturi "(?&amp;lt;prefix&amp;gt;\S+)/locations/(?&amp;lt;method&amp;gt;\w+[^/?])" 
| table ResponseTime method&lt;/LI-CODE&gt;&lt;P&gt;This is resulted in below output&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;STRONG&gt;ResponseTime&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;STRONG&gt;Method&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;330&lt;/TD&gt;&lt;TD width="50%"&gt;A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1627&lt;/TD&gt;&lt;TD width="50%"&gt;B&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1025&lt;/TD&gt;&lt;TD width="50%"&gt;B&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3126&lt;/TD&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2034&lt;/TD&gt;&lt;TD&gt;B&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;..........................&lt;/TD&gt;&lt;TD&gt;...............&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I have two possibilities for method (Say for ex: A and B)&lt;/P&gt;&lt;P&gt;I want to get results something like below (Responsetime and count of each method falling in that interval)&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;&lt;STRONG&gt;ResponseTime&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;&amp;lt;=1000&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;4&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;&amp;gt;1000 and &amp;lt;=3000&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;11&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;25&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;&amp;gt;3000 and &amp;lt;=5000&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;35&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;gt;5000&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help me with the query!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 08:52:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642624#M222586</guid>
      <dc:creator>Splunk_321</dc:creator>
      <dc:date>2023-05-09T08:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to group multiple methods responsetime into intervals and obtain count?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642710#M222605</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251203"&gt;@Splunk_321&lt;/a&gt;&amp;nbsp;- try below search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;basesearch 
| eval ResponseTime=if(uri=="/api/auth",null(),responsetime*1000) 
| rex field=gwrequesturi "(?&amp;lt;prefix&amp;gt;\S+)/locations/(?&amp;lt;method&amp;gt;\w+[^/?])" 
| table ResponseTime method

| eval category=case(ResponseTime&amp;lt;=1000,"&amp;lt;=1000", ResponseTime&amp;lt;=3000,"&amp;gt;1000 and &amp;lt;=3000", ResponseTime&amp;lt;=5000,"&amp;gt;3000 and &amp;lt;=5000", ResponseTime&amp;gt;5000,"&amp;gt;5000")
| chart count over category by Method&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I hope this helps!!! Kindly upvote if it does!!!&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 17:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642710#M222605</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-09T17:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to group multiple methods responsetime into intervals and obtain count?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642758#M222625</link>
      <description>&lt;P&gt;This helps. Thank you for the solution!&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 04:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-multiple-methods-responsetime-into-intervals-and/m-p/642758#M222625</guid>
      <dc:creator>Splunk_321</dc:creator>
      <dc:date>2023-05-10T04:49:37Z</dc:date>
    </item>
  </channel>
</rss>

