Other Usage

How to get the data from splunk

aditsss
Motivator

Hi Everyone ,

I have two applications and I have created dashboards forteh apps:

index=epaas_epaas2_idx ns=blazegateway app_name=blazecrsgateway*

I need to get the below info:

  1. Total YTD Volume for PSF Push API
  2. Total Volume to GRS YTD

Can someone guide me how we can get the above two information with index,ns and app name.

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

could you better describe your request:

  • YTD is a numeric field to sum?
  • what's the field to sum to have Total Volume?
  • what are "PSF Push API" and "GRS YTD", values of a field? what field?

Anyway, if I correctly supposed your fields and if they all are fields, you could run something like this:

index=epaas_epaas2_idx ns=blazegateway app_name=blazecrsgateway*
| stats 
     sum(YTD) AS "Total YTD Volume" 
     sum(Volume) AS GRS YTD 
     values(index) AS index 
     values(ns) AS ns 
     values(app_name) AS app_name 
     BY PSF_Push_API

At least I hint to follow the Splunk Search Tutorial (https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchTutorial/WelcometotheSearchTutorial) to be autonomous in your searches.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...