Splunk Search

Splunk Query to get Error rate percentage

sonal
New Member

I want to have a query that can show me the percentage of error rate in the "AccountDetailsController" service of my application. We have the metrics data coming in from splunk so If that has to be used or however we can do this. Please help

Labels (3)
0 Karma

sonal
New Member

But from where to find the field that are to be used in the query. I cannot find it anywhere. Only this information is present in "builtin:service.errors.server.rate " metrics :

1/5/24
5:10:00.000 AM
{ [-]
   MessageDeduplicationId
   aggregationavg
   entity.service.idSERVICE-xxxxx
   entity.service.nameAccountDetailsControllerImpl
   metric_name:builtin:service.errors.server.rate3.8461538461538463
   resolution1m
   source.nameDT_Prod_SaaS
   unitPercent



0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

there are already quite many examples about this (or at least with event data). You could find those with search "site:splunk.com calculate error rate". You must just modify those to work with metric index if you have stored that data into those.

r. Ismo

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...