Splunk Search

Count of requests processed by each API service per minute.

nithys
Communicator

Hi 

I am working on below query to get Count of requests processed by each API service per minute

index=np source IN ("/aws/lambda/api-data-test-*") "responseTime"
| eval source = if(match(source, "/aws/lambda/api-data-test-(.*)"), replace(source, "/aws/lambda/api-data-test-(.*)", "data/\\1"), source)
| bucket _time span=1m | stats count by source, _time

i get below result for one source "name"
,second source by address,third source by city .
How can i represent different api source with per minute in good understandable format...either graph or pictorial representation

source _time count     

 
data/name2025-03-02 08:13:002 
data/name2025-03-02 08:14:0057 
data/name2025-03-02 08:15:00347 
data/name2025-03-02 08:16:0062 
data/name2025-03-02 08:17:0048 
 
data/address2025-03-02 08:18:0021 
data/city2025-03-02 08:19:0066 
data/city2025-03-02 08:20:0055 
data/address2025-03-02 08:21:007 

name event

{"name":"log","awsRequestId":"aws","hostname":"1","pid":8,"level":30,"requestType":"GET","entity":"name","client":"Ha2@gmail.com","domain":"name.io","queryParams":{"identifier":"977265"},"responseTime":320,"msg":"responseTime","time":"2025-03-02T03:23:40.504Z","v":0}

address event

{"name":"log","awsRequestId":"aws","hostname":"1","pid":8,"level":30,"requestType":"GET","entity":"address","client":"Harggg2@gmail.com","domain":"name.io","queryParams":{"identifier":"977265"},"responseTime":320,"msg":"responseTime","time":"2025-03-02T03:23:40.504Z","v":0}



Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Do you mean something like this?

index=np source IN ("/aws/lambda/api-data-test-*") "responseTime"
| eval source = if(match(source, "/aws/lambda/api-data-test-(.*)"), replace(source, "/aws/lambda/api-data-test-(.*)", "data/\\1"), source)
| timechart span=1m count by source

 

Tags (1)

nithys
Communicator

Thank you @yuanliu It worked

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...