Splunk Search

How to get the response time value?

neeldesai1992
Path Finder

I want to get the response time in terms of value(a Number). How can I get it? Following script returns me the visual representation of response time not in number. I want to get the number.

index=abc source=XYZ buildNumber=13 type=REQUEST

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Is this what you are looking for: index=abc source=XYZ buildNumber=13 type=REQUEST | table wholeduration?

View solution in original post

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Is this what you are looking for: index=abc source=XYZ buildNumber=13 type=REQUEST | table wholeduration?

0 Karma

neeldesai1992
Path Finder

I was thinking the same. Do you know how to display any eval value? Means let's say I am doing eval total =val1+val2 . now how can I display the result of it? If I use table command, it is not displaying my previous stats values and also not displaying value.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

The field 'total' will show up as a field in the field list on the left hand side of the search&reporting app. If you want to show it in a table, just add | table total. It behaves like any other field.

stats is a reporting command and will only output the values it produces. Maybe you can describe what you are trying to do in a bit more detail so we can help you get to the proper solution...?

If you have something like mysearch | eval a=b+c | stats count by xyz then you will only see the count value, unless you do mysearch | eval a=b+c | stats count by xyz values(a) as a but whether that gives you the right result is hard to predict without knowing what specific problem you are trying to solve.

0 Karma

DalJeanis
Legend

From what you describe, you are looking at the Visualization tab.

Click to the events tab.

0 Karma

neeldesai1992
Path Finder

Sorry my bad , i am seeing this in events tab.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

If you share a sample event it would easier for us to help you. With what you have given us, we don't know what fields you have available.

0 Karma

neeldesai1992
Path Finder

10/9/17
7:38:03.000 AM

{ [-]
buildNumber: 14
date: 2017-10-09T07:33:21.973Z

endReqDate: 10/09/2017:07:09:55

endrelative: 260888
endtimereq: 1507532995010

scenarioClass: com.xyz.abc
scenarioStep: post scenario

startReqDate: 10/09/2017:07:09:54

startrelative: 260859
starttimereq: 1507532994981

status: KO
statusMessage: status.find.in(200,304,201,202,203,204,205,206,207,208,209), but actually found 503

type: REQUEST

userid: 111245
wholeduration: 29
}

0 Karma

neeldesai1992
Path Finder

when I run the above splunk search query it just return me the response time in terms of chart/graph not in terms of value

0 Karma

sbbadri
Motivator

can you please paste complete search query.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...