Splunk Search
Highlighted

How to write a search to get a table of eventstats perc95 and avg by a certain field?

Path Finder

I need a table which gives me both perc95(responsetime) and avg(responsetime) by service_name
I am using the below query, but is giving me some weird results...

index=jms_logs sourcetype=perflogs | eventstats perc95(response_time) as response_time_95p, avg(response_time) as avgRespTime | stats by service_name

can someone please help me?
Thanks.

Tags (3)
Highlighted

Re: How to write a search to get a table of eventstats perc95 and avg by a certain field?

SplunkTrust
SplunkTrust

Try this

 index=jms_logs sourcetype=perflogs | stats perc95(response_time) as response_time_95p, avg(response_time) as avgRespTime by service_name

View solution in original post

Highlighted

Re: How to write a search to get a table of eventstats perc95 and avg by a certain field?

Path Finder

thanks. It worked just great.

0 Karma