I want to plot the 90 percentile response time in Splunk. Is the below correct?
| timechart p90(ResponseTime)
or is the below correct
eventstats avg(ResponseTime) as ttavg | eventstats p90(ttavg) as p90avg | timechart max(p90avg)
HI
try this perc90(ttavg ) instead of p90(ttavg)
eventstats avg(ResponseTime) as ttavg | eventstats perc90(ttavg) as perc90_avg | timechart max(perc90_avg)
see also these links
https://answers.splunk.com/answers/99632/what-does-perc95-and-all-those-stats-functions-perc.html
https://answers.splunk.com/answers/8690/90th-percentile-search-results.html
This is the right syntax
perc90()
Thanks,
Raghav