Splunk Search

Splunk REST Query Returns No Data for stats

chrisboy68
Contributor

Hi,

Given the below search:

 

 

index="my_index" source="mysource"  _index_earliest=-1h 
|  rex field=_raw "\:\sPT(?P<respt>\d+\.\d+)" 
| fields response_time_ms respt| convert num(respt) as response_time_ms 
| eval response_time_ms = response_time_ms*1000  
| stats exactperc95(response_time_ms) as myPercent

 

 

Works fine in the UI, but when I try to execute through the API i get no data back and an obscure message.

 

 

 myPercent Specified field(s) missing from results: 'response_time_ms' myPercent 

 

 

 

Can't figure out what is going on, I have listed the field in "rf" with no luck. I do have search API working for other info, so I know credentials and my POST is accurate. Is there a limitation on stats?

Thanks

 

Chris

Labels (2)
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...