Splunk Enterprise

How to plot response time against _time field

shashank_24
Path Finder

Hi, I am trying to plot the response time values against _time field. I am aware of the timechart and stats command which i can use to calculate the average or percentile but what i would want is to plot the actual values over time.

I have the below query where I want field responseTime on y-axis vs _time on x-axis with actual values and not the average. Is that possible to do without using transforming commands?

index=test host="serverer-p*" RESPONSE "uri=[/checkout/my-app]" 
| rex field=_raw"\[(?<responseTime>[^\s]+)"

 

Labels (1)
Tags (3)
0 Karma

renjith_nair
SplunkTrust
SplunkTrust

What happens if you just add

|table _time,responseTime  and select a visualization

Happy Splunking!

shashank_24
Path Finder

@renjith_nair You would say I was stupid. I was actually trying that but instead of table I was using fields command. With table command it works. Thank you.

index=test host="serverer-p*" RESPONSE "uri=[/checkout/my-app]" 
| rex field=elapsedTime "\[(?<responseTime>[^\s]+)"
| table _time responseTime

 

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@shashank_24, glad to know 🙂 .  Appreciate an upvote and you may close the question by accepting as a solution

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...