Splunk Search

How to calculate transaction per second for my search?

abzmhzsplunk
New Member

for the search

index=* some_events | stats count

how to calculate the transaction per second for this search (how to get how many seconds for the search job)?
tried to use |addinfo | eval t=info_max_time - info_min_time but couldn't get it to work.
please help.
thanks.

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

index=* | addinfo | eval t=info_max_time - info_min_time | stats count as ct max(t) as t | eval tps=ct/t |table ct, tps

View solution in original post

somesoni2
Revered Legend

Try this

index=* | addinfo | eval t=info_max_time - info_min_time | stats count as ct max(t) as t | eval tps=ct/t |table ct, tps

lguinn2
Legend

addinfo doesn't tell you anything about how long it took your search to run - it gives some access to information about your search, but not that.

An administrator can tell how long a search ran by looking in the _audit index like this

index=_audit action=search user!="splunk-system-user" info=completed
| table user search_id total_run_time exec_time scan_count event_count _time

I used the table just to show an example of the results...

0 Karma

abzmhzsplunk
New Member

How to calculate how many seconds already run in my search? That is what I want.

0 Karma

somesoni2
Revered Legend

Are you trying to calculate, for your search, number of rows in the base search/time it took to execute; OR just for your events, how many events are coming to your indexes per second (count/time range in secs)?

0 Karma

abzmhzsplunk
New Member

Here is what I tried
index=* | addinfo | eval t=info_max_time - info_min_time | stats count as ct | eval tps=ct/t |table ct, tps

I want to find out total count for the search and the time of the search, then calculate tps="total count" / "time in seconds for the search"

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...