Getting Data In

Why is Splunk rest api result not returning aggregated field?

santoshbwn
New Member
search index=abc dp_"response"| stats perc95(api_time_taken) as abc by api

 

This is the search query I am using while invoking through splunk rest API.

In the result, I am not getting the abc field, only the API values are listed . Is there anything specific I need to do to include perc95,avg or max values in the result.

 

From UI, it works completely fine where it shows the abc column with the 95 percentile value

If someone can guide me, it would be really helpful.

 

Thanks,

Santosh

Thank,

Santosh

0 Karma

kilimche
Explorer

Hi, @santoshbwn any update on your issue?

0 Karma

kilimche
Explorer

Hi, any update on your issue, Im facing similar problem when reading from SPLUNK Rest APi via ADF using 

| eval compliant=if(Days<60, "Yes", "No")]
| chart count(host) by system compliant | addtotals | eval No=round((100*No/Total),2) | eval Yes=round((100*Yes/Total),2) | fields – Total Yes No

 

I see the correct result via UI but only the summary in the ADF result

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...