I am having a question regarding log details in Splunk.
1.How response time is generating in logs.?
2.From where it gets configured?
what do you mean with "response time"?
in Splunk there are two timestamps:
If instead you're speaking of a field in event (e.g. milliseconds from a web transactions) you have to extract it using a regex.
this is a very generic question!
Anyway, if you can clearly identify your transactions (e.g. using a unique Transaction ID to group all the events of a transaction) you can use more solutions to calculate the duration of the transaction.
The easiest way, but not the more performant is the transaction command (see to https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Transaction ).
Otherway you can use the stats command, that's faster than the other, try somerhng like this:
Your_search | stats earliest(_time) AS earliest latest(_time) AS latest BY transaction_ID | eval duration=latest-earliest | table transaction_ID duration