Splunk Search

Can We add diffrent search timing

ravindra_ap
Explorer

Hi,

Is it possible to run the same search with diffrent search time?

My requirement to have the count of transaction for particular hour in last 5 weeks , report looks as below:

Tran Type 25/Apr/13 07.00 -08.00 24/Apr/13 07.00 -08.00 23/Apr/13 07.00 -08.00

Get 100 80 95
Post 90 78 102

Tags (1)
0 Karma

_d_
Splunk Employee
Splunk Employee

Appending/subsearches can be pretty expensive in terms of performance and sometimes pretty hard to keep track of. What you probably need here is to run a single search over the last 5 weeks (or days, or whatever your window is) BUT scope it to the right hour interval. For example, this search will go back 5 days, search only between 9pm and 10pm and chart the count of events per method (GET or POST) for said slot of each day:

index=_internal source=*access* date_hour=21 earliest=-5d | chart count over method by date_mday

martin_mueller
SplunkTrust
SplunkTrust

You could run five subsearches appended to each other, with one set to the one hour you're looking for each week.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Sure. This looks for the count of events in _internal for the past hour plus the same time in the past few weeks:

index=_internal earliest=-h | stats count | addinfo | append [search index=_internal earliest=-w-h latest=-w | stats count | addinfo] | append [search index=_internal earliest=-2w-h latest=-2w | stats count | addinfo] | append [search index=_internal earliest=-3w-h latest=-3w | stats count | addinfo] | append [search index=_internal earliest=-4w-h latest=-4w | stats count | addinfo] | fieldformat info_max_time = strftime(info_max_time, "%+") | fields count info_max_time
0 Karma

ravindra_ap
Explorer

Thanks Martin. Can you please give the example query if you have any as I am not sure how we can give the search time inside the search querty?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...