Splunk Search

Display Time Taken in Splunk response

jdhavo
New Member

I would like to display the time taken for a page to load in Splunk. Here is my query:

splunk_server=* index="myindex1" host=NA*P* host=COSERVER313 | convert num(time_taken) | sort 100 -time_taken

Here is the result:
splunk_server=* index="myindex1" host=NA*P* host=COSERVER313 | convert num(time_taken) | sort 100 -time_taken
2/28/19
1:59:28.000 AM

2019-02-28 06:59:28 W3SVC21 10.121.3.95 GET /en/mypage1/publications/documents/2016-documents/w112-document1.aspx - 443 - 10.121.3.101 Mozilla/5.0+(compatible;+search-crawler-EXTERNAL;++null;+SYS.COM.Search.Team@company.org) - 200 0 64 0 555 265525 54.88.115.238
host = COSERVER313 source = E:\ywlogs\company\IIS\W3SVC21\u_ex190228_x.log sourcetype = iis
2/28/19

Tags (1)
0 Karma

renjith_nair
Legend

@jdhavo,
Where is the problem now ? Are you not getting time_taken value? is that a field?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...