Monitoring Splunk

Splunk query for getting logs in descending order based on API execution time

athul_r_m
New Member

Can some one help me with query for getting logs in descending order based on API execution time which printed on logs.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @athul_r_m,

your request is just a little too vague!

could you better describe your data?

e.g. fields to display, API execution time fieldname, etc...

Anyway, to sort in descrnding order you have to see the options of the sort command (https://docs.splunk.com/Documentation/SCS/current/SearchReference/SortCommandOverview😞

index=your_index
| sort -API_execution_time
| table API_execution_time field1 field2 field3 

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...