Splunk Search

How do I create a chart with the x-axis as processing time for transactions and the y-axis as number of events?

gowthamkb
Explorer
 Location          Processing Time (minutes)               
 -----------       ---------------------------
 Central           21.6                                     
 South East        27.4     

How do I generate a report with my x-axis as 'Processing time' and y-axis as Number of events? With this report, I want to get the time taken by transactions. Any help is appreciated. Thanks in advance.

0 Karma
1 Solution

twinspop
Influencer

Assuming your duration field is processing_time:

... | bin processing_time bins=10 | chart count over processing_time

The bin command has many more options to tweak this as required.

http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Bin

View solution in original post

0 Karma

sundareshr
Legend

This should give you processing time in x-axis, but not sure how you can calculate txn totals.

... | stats count by "Processing Time (minutes)"
0 Karma

twinspop
Influencer

Assuming your duration field is processing_time:

... | bin processing_time bins=10 | chart count over processing_time

The bin command has many more options to tweak this as required.

http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Bin

0 Karma

gowthamkb
Explorer

Thank you !

0 Karma

gowthamkb
Explorer

Location Processing Time (minutes) trans_date


Central 21 09/21/2016
South East 40 09/22/2016

Is there a way I can get a bar chart with time buckets , y-axis-primary showing percentage (transactions), y-axis secondary showing processing_time (0-10 mins, 10-20 mins etc) and x axis showing trans_date ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...