Splunk Search

Display Time Taken in Splunk response

jdhavo
New Member

I would like to display the time taken for a page to load in Splunk. Here is my query:

splunk_server=* index="myindex1" host=NA*P* host=COSERVER313 | convert num(time_taken) | sort 100 -time_taken

Here is the result:
splunk_server=* index="myindex1" host=NA*P* host=COSERVER313 | convert num(time_taken) | sort 100 -time_taken
2/28/19
1:59:28.000 AM

2019-02-28 06:59:28 W3SVC21 10.121.3.95 GET /en/mypage1/publications/documents/2016-documents/w112-document1.aspx - 443 - 10.121.3.101 Mozilla/5.0+(compatible;+search-crawler-EXTERNAL;++null;+SYS.COM.Search.Team@company.org) - 200 0 64 0 555 265525 54.88.115.238
host = COSERVER313 source = E:\ywlogs\company\IIS\W3SVC21\u_ex190228_x.log sourcetype = iis
2/28/19

Tags (1)
0 Karma

renjith_nair
Legend

@jdhavo,
Where is the problem now ? Are you not getting time_taken value? is that a field?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...