Splunk Search

How do I create a chart with the x-axis as processing time for transactions and the y-axis as number of events?

gowthamkb
Explorer
 Location          Processing Time (minutes)               
 -----------       ---------------------------
 Central           21.6                                     
 South East        27.4     

How do I generate a report with my x-axis as 'Processing time' and y-axis as Number of events? With this report, I want to get the time taken by transactions. Any help is appreciated. Thanks in advance.

0 Karma
1 Solution

twinspop
Influencer

Assuming your duration field is processing_time:

... | bin processing_time bins=10 | chart count over processing_time

The bin command has many more options to tweak this as required.

http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Bin

View solution in original post

0 Karma

sundareshr
Legend

This should give you processing time in x-axis, but not sure how you can calculate txn totals.

... | stats count by "Processing Time (minutes)"
0 Karma

twinspop
Influencer

Assuming your duration field is processing_time:

... | bin processing_time bins=10 | chart count over processing_time

The bin command has many more options to tweak this as required.

http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Bin

0 Karma

gowthamkb
Explorer

Thank you !

0 Karma

gowthamkb
Explorer

Location Processing Time (minutes) trans_date


Central 21 09/21/2016
South East 40 09/22/2016

Is there a way I can get a bar chart with time buckets , y-axis-primary showing percentage (transactions), y-axis secondary showing processing_time (0-10 mins, 10-20 mins etc) and x axis showing trans_date ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...