Monitoring Splunk

Splunk query for getting logs in descending order based on API execution time

athul_r_m
New Member

Can some one help me with query for getting logs in descending order based on API execution time which printed on logs.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @athul_r_m,

your request is just a little too vague!

could you better describe your data?

e.g. fields to display, API execution time fieldname, etc...

Anyway, to sort in descrnding order you have to see the options of the sort command (https://docs.splunk.com/Documentation/SCS/current/SearchReference/SortCommandOverview😞

index=your_index
| sort -API_execution_time
| table API_execution_time field1 field2 field3 

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...