- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to append tp99 and tp90 in the existing query?
VikhyathMaiya
Explorer
02-15-2022
11:26 AM
Hello Splunk community. I have a query that is running currently as shown below:
index=myIndex* api.metaData.pid="my_plugin_id" | rename api.p as apiName | chart count BY apiName "api.metaData.status" | multikv forceheader=1
| table apiName success error NULL
| eval line=printf("%-85s% 10s% 10s% 7s",apiName, success, error, NULL)
| stats list(line) as line
| eval headers=printf("%-85s% 10s% 10s% 7s","API Name","Success","Error", "NULL")
| eval line=mvappend(headers,line)
| fields - headers
Which displays a table with "API Name","Success","Error", "NULL" counts. This works as expected.
Now i want to add a new column in the table which displays the latency value (tp95 and tp99) for each apiName . The time taken by each api is in the field api.metadata.tt.
How can i achieve this ? I am new to splunk and I am literally stuck at this point. Could someone please help me. Thank you 🙂
Info: Just to let you guys know, my query has these additional logic to format things because of related question here
Now i want to add a new column in the table which displays the latency value (tp95 and tp99) for each apiName . The time taken by each api is in the field api.metadata.tt.
How can i achieve this ? I am new to splunk and I am literally stuck at this point. Could someone please help me. Thank you 🙂
Info: Just to let you guys know, my query has these additional logic to format things because of related question here
