Monitoring Splunk

Calculate max TPS over period of time (2 months) everyday

dantu
Explorer

HI,

I want to get the max TPS over period of time per day (last 2 months). Any idea what would be the ideal way to do this?

I tried a query but i am not sure to get it per day

index=xyz host=xyz*web* NOT _ui AND NOT medias AND NOT "/backoffice" AND "HTTP/1.1\" 200" | timechart span=1s count AS TPS | eventstats max(TPS) as peakTPS | eval peakTime=if(peakTPS==TPS,_time,null()) | stats avg(TPS) as avgTPS first(peakTPS) as peakTPS

Tags (1)
0 Karma

ssadanala1
Contributor

index=xyz host=xyz*web* NOT _ui AND NOT medias AND NOT "/backoffice" AND "HTTP/1.1\" 200"|bin _time span=1d | stats max(TPS) as c by _time .

Gives you maximum vlaues of TPS per day

or you can use

index=xyz host=xyz*web* NOT _ui AND NOT medias AND NOT "/backoffice" AND "HTTP/1.1\" 200"| timechart span=1d max(current_size) as c

dantu
Explorer

but this wont give me the TPS right? span here is 1d?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese and ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...