Splunk Search

Compare set of data from different times

karche
Path Finder

I have the following query to capture the application response time, and put it in summary index
source=iislog app="abc" | sistats avg(time_taken) count by source
index=summary search_name="capture app response time" | timechart span=1d avg(time_taken) by orig_source.

I would like to create a report that i can compare the response time for this week, last week and 4 weeks ago in the same report. How can i do that?

Thanks in advance.

Tags (1)
1 Solution

carasso
Splunk Employee
Splunk Employee

Comparing week-over-week results used to a pain in Splunk, with complex date calculations. No more. Now there is a better way.

I wrote a convenient search command called "timewrap" that does it all, for arbitrary time periods.

... | timechart count span=1h | timewrap w

That's it!

http://apps.splunk.com/app/1645/

View solution in original post

carasso
Splunk Employee
Splunk Employee

Comparing week-over-week results used to a pain in Splunk, with complex date calculations. No more. Now there is a better way.

I wrote a convenient search command called "timewrap" that does it all, for arbitrary time periods.

... | timechart count span=1h | timewrap w

That's it!

http://apps.splunk.com/app/1645/

RicoSuave
Builder

The easiest way to do this is by bucketing your _time field and then charting over it. Try this

index=summary search_name="capture app response time" | bucket _time span=1w | chart avg(time_taken) over _time by orig_source

This should produce a nice table with weekly averages. Run this over a month period and it should show what you are looking for.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...