Splunk Search

How to calculate transaction per second for my search?

abzmhzsplunk
New Member

for the search

index=* some_events | stats count

how to calculate the transaction per second for this search (how to get how many seconds for the search job)?
tried to use |addinfo | eval t=info_max_time - info_min_time but couldn't get it to work.
please help.
thanks.

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

index=* | addinfo | eval t=info_max_time - info_min_time | stats count as ct max(t) as t | eval tps=ct/t |table ct, tps

View solution in original post

somesoni2
Revered Legend

Try this

index=* | addinfo | eval t=info_max_time - info_min_time | stats count as ct max(t) as t | eval tps=ct/t |table ct, tps

lguinn2
Legend

addinfo doesn't tell you anything about how long it took your search to run - it gives some access to information about your search, but not that.

An administrator can tell how long a search ran by looking in the _audit index like this

index=_audit action=search user!="splunk-system-user" info=completed
| table user search_id total_run_time exec_time scan_count event_count _time

I used the table just to show an example of the results...

0 Karma

abzmhzsplunk
New Member

How to calculate how many seconds already run in my search? That is what I want.

0 Karma

somesoni2
Revered Legend

Are you trying to calculate, for your search, number of rows in the base search/time it took to execute; OR just for your events, how many events are coming to your indexes per second (count/time range in secs)?

0 Karma

abzmhzsplunk
New Member

Here is what I tried
index=* | addinfo | eval t=info_max_time - info_min_time | stats count as ct | eval tps=ct/t |table ct, tps

I want to find out total count for the search and the time of the search, then calculate tps="total count" / "time in seconds for the search"

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...