Splunk Search

Response time

Als123
Explorer

Hi Team,

I am having a question regarding log details in Splunk.

1.How response time is generating in logs.?

2.From where it gets configured?

Labels (1)
0 Karma

Als123
Explorer

@gcusello ,

Thank you. Got it now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Als123,

what do you mean with "response time"?

in Splunk there are two timestamps:

  • _time: the timestamp of the event, extracted during indexing from the event with rules defined in props.conf,
  • _indextime: the timestamp associated to the event when the event is indexed by Splunk.

If instead you're speaking of a field in event (e.g. milliseconds from a web transactions) you have to extract it using a regex.

Ciao.

Giuseppe

Als123
Explorer

Hi @gcusello ,

In my logs, I couldn't able to see the response time of the transaction.How to get that one?Can you please help me?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Als123,

this is a very generic question!

Anyway, if you can clearly identify your transactions (e.g. using a unique Transaction ID to group all the events of a transaction) you can use more solutions to calculate the duration of the transaction.

The easiest way, but not the more performant is the transaction command (see to https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Transaction ).

Otherway you can use the stats command, that's faster than the other, try somerhng like this:

Your_search
| stats earliest(_time) AS earliest latest(_time) AS latest BY transaction_ID
| eval duration=latest-earliest
| table transaction_ID duration

 Ciao.

Giuseppe

0 Karma

Als123
Explorer

Hi @gcusello ,

Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Als123,

if this answer solves your need, please accept it for the other people of Community.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...