Splunk Search

Min and Max Response Time

rj1408
Path Finder

Hi I want to calculate Min and Max Response time only if the status is success.

Below is the table format:


MicroServiceTotal_TransactionSuccessFailureAvgFailure%Success%Min_Response_TimeMax_Response_time
         
LostStolenCard752522328.5771.43  
CreditLimit1501543240100  
Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval successTime = if(staus="Success", responseTime, null)
| stats max(successTime) as Max_Response_time min(successTime) as Min_Response_Time by MicroService

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You can calculate the numbers then delete them if the status is not success.

... | stats min(ResponseTime) as Min_Response_Time, max(ResponseTime) as Max_Response_Time by MicroService
| eval Min_Response_Time=if(Status=0,null,Min_Response_Time), Max_Response_Time=if(Status=0,null, Max_Response_Time)
---
If this reply helps you, Karma would be appreciated.

ITWhisperer
SplunkTrust
SplunkTrust
| eval successTime = if(staus="Success", responseTime, null)
| stats max(successTime) as Max_Response_time min(successTime) as Min_Response_Time by MicroService

rj1408
Path Finder
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...