Splunk Search

Search pages based on their response time

Explorer

I need to know the pages, along with the count of how many times their response time exceeded 100. I need the top 10 such pages ordered by their count. I wrote the following search query, but did not get success. Please help.

...| eval timesec = round(timetaken/1000) | where timesec > 100 | stats count as cnt by csuri_stem | sort cnt 10 -

Ultra Champion

You don't provide a sample of your logs, but from what you write, I assume that something like the following would do what you want;

sourcetype=your_sourcetype time_taken > 100000 | top cs_uri_stem

Hope this helps,

Kristian

0 Karma