Hello, i think its not that difficult, but i dont know how to do it.
The result is in milliseconds. Is there an easy way to convert these milliseconds into seconds?
Best regards
Hello exchanger,
You can use the eval fonction.
Try this :
Your search
| stats avg(duration) as avg_duration, perc50(duration) as perc50_duration, perc75(duration) as perc75_duration, max(duration) as max_duration
| eval avg_duration = avg_duration / 1000
And you can do that for each field if you want.
Let me know if it helps you 🙂
Hello exchanger,
You can use the eval fonction.
Try this :
Your search
| stats avg(duration) as avg_duration, perc50(duration) as perc50_duration, perc75(duration) as perc75_duration, max(duration) as max_duration
| eval avg_duration = avg_duration / 1000
And you can do that for each field if you want.
Let me know if it helps you 🙂
Yes it's possible.
The worst (but working) solution is using the append function (https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/Append)
I said worst because it's not the most efficient way.
If you need help for that you should create another post, and if possible put all the queries you want to merge, someone will help you 🙂
For this post, you can mark my answer as the solution to close it
Thanks for this information. I used the append function and it worked 🙂