Other Usage

How to get the data from splunk

aditsss
Motivator

Hi Everyone ,

I have two applications and I have created dashboards forteh apps:

index=epaas_epaas2_idx ns=blazegateway app_name=blazecrsgateway*

I need to get the below info:

  1. Total YTD Volume for PSF Push API
  2. Total Volume to GRS YTD

Can someone guide me how we can get the above two information with index,ns and app name.

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

could you better describe your request:

  • YTD is a numeric field to sum?
  • what's the field to sum to have Total Volume?
  • what are "PSF Push API" and "GRS YTD", values of a field? what field?

Anyway, if I correctly supposed your fields and if they all are fields, you could run something like this:

index=epaas_epaas2_idx ns=blazegateway app_name=blazecrsgateway*
| stats 
     sum(YTD) AS "Total YTD Volume" 
     sum(Volume) AS GRS YTD 
     values(index) AS index 
     values(ns) AS ns 
     values(app_name) AS app_name 
     BY PSF_Push_API

At least I hint to follow the Splunk Search Tutorial (https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchTutorial/WelcometotheSearchTutorial) to be autonomous in your searches.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...