Splunk Search

After splunk job failed, we are unable to fetch the every 5 mins history data.

DKR1
New Member

@links to members

'search earliest=-10m latest=now index= 'xyz'

(host=abcd123 or host=abcd345)

TxnStart2End| rex "Avg=(?<avgRspTime>\d+)"  | rex "count=(?<count>\d+)"  |timechart span=5m

sum(count) as Vol,

avg(avgrsptime) as "ART" | eval TPS=(vol/300) | table _time Vol Avgresptime TPS | sort_time'

 

the above query will fetch every 5 mins records so no worries but the issue is if the splunk job failed and run after half an hour for example:

 

suppose my job last run is 10:00am  and it fetch records until 10:00 AM for every 5 mins spam.

my job got failed at 10:01 am and it will run again at 11:00 am, but in between 10:01 am to 11:00 am data is missing ( so my requirement is I need missing data in the spam of for every 5 mins)

i.e 10:05 data, 10:10 data ...10:50, 10:55 and 11:00 data..

please help with correct query.

Labels (1)
0 Karma

somesoni2
Revered Legend

How frequently your Splunk job runs (cron schedule)? What do you do with generated report?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...