Monitoring Splunk

Query to cumulate endpoint uri

saireddy
Loves-to-Learn Lots

How to get cumulate response times for below endpoint.  
Below is the query i tried. but need similar endpoints should be cumulated together instead of separate endpoint. 

| stats values(pod) as HOST count avg(ReqProcessTime) as Avg p90(ReqProcessTime) as "Percentile90" max(ReqProcessTime) as Max by endpointURI, servicename, ResponseCode

saireddy_0-1638790346200.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval endpointURI=replace(endpointURI,"[^/]+$","")
0 Karma

saireddy
Loves-to-Learn Lots

Thanks ,

 

Incase we if have static endpoint in the log. which is like below this is getting replaced by 
/services/renewals/".  

Original Endpoint - /services/renewals/renewaldetails


so, whenever there are common endpoints they should be added. if they are static it should display as is.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...