Splunk Search

Calculate performance metrics for different categories in a single search

ebs
Communicator

Hi,

Bit out of my depth here but I have done an eval so we divide the events in the index by the URLs and I have 4 categories. Each category has a different response_time threshold and the search ultimately will calculate how many events in each category fall into the acceptable range of that threshold. 

How do I do this? 

I thought of maybe doing a total count by category but then I have no idea how to do a search within the same search on whether the events within the categories fall into the unique threshold parameters. Do I need to do subsearches?

Labels (4)
0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...