Getting Data In

Splunk rest api result not returning aggregated field

New Member

search index=abc dp_"response"| stats perc95(api_time_taken) as abc by api


This is the search query I am using while invoking through splunk rest API.

In the result, I am not getting the abc field, only the API values are listed . Is there anything specific I need to do to include perc95,avg or max values in the result.


From UI, it works completely fine where it shows the abc column with the 95 percentile value

If someone can guide me, it would be really helpful.






Labels (1)
0 Karma