Splunk Search

Splunk Query to get Error rate percentage

sonal
New Member

I want to have a query that can show me the percentage of error rate in the "AccountDetailsController" service of my application. We have the metrics data coming in from splunk so If that has to be used or however we can do this. Please help

Labels (3)
0 Karma

sonal
New Member

But from where to find the field that are to be used in the query. I cannot find it anywhere. Only this information is present in "builtin:service.errors.server.rate " metrics :

1/5/24
5:10:00.000 AM
{ [-]
   MessageDeduplicationId: 
   aggregation: avg
   entity.service.id: SERVICE-xxxxx
   entity.service.name: AccountDetailsControllerImpl
   metric_name:builtin:service.errors.server.rate: 3.8461538461538463
   resolution: 1m
   source.name: DT_Prod_SaaS
   unit: Percent



0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

there are already quite many examples about this (or at least with event data). You could find those with search "site:splunk.com calculate error rate". You must just modify those to work with metric index if you have stored that data into those.

r. Ismo

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...