Monitoring Splunk

Splunk query for getting logs in descending order based on API execution time

athul_r_m
New Member

Can some one help me with query for getting logs in descending order based on API execution time which printed on logs.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @athul_r_m,

your request is just a little too vague!

could you better describe your data?

e.g. fields to display, API execution time fieldname, etc...

Anyway, to sort in descrnding order you have to see the options of the sort command (https://docs.splunk.com/Documentation/SCS/current/SearchReference/SortCommandOverview😞

index=your_index
| sort -API_execution_time
| table API_execution_time field1 field2 field3 

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...