But from where to find the field that are to be used in the query. I cannot find it anywhere. Only this information is present in "builtin:service.errors.server.rate " metrics :
| 1/5/24 5:10:00.000 AM | { [-] MessageDeduplicationId: aggregation: avg entity.service.id: SERVICE-xxxxx entity.service.name: AccountDetailsControllerImpl metric_name:builtin:service.errors.server.rate: 3.8461538461538463 resolution: 1m source.name: DT_Prod_SaaS unit: Percent |
Hi
there are already quite many examples about this (or at least with event data). You could find those with search "site:splunk.com calculate error rate". You must just modify those to work with metric index if you have stored that data into those.
r. Ismo