Splunk Search
Highlighted

extracting response status time

New Member

How can i extract the the httpresponsetime so that i can get the max(HTTPSTATUSRESPONSE), MIN(HTTPSTATUSRESPONSE) and median(HTTPSTATUSRESPONSE). from the following events

6/28/19 9:05:26.760 AM INFO 2019-06-28 05:05:26,760 ------- [[------_rrfi.zip].throttling-task.01] LoggerMessageProcessor AFTER: IP_address: ....... API_name: ........ server ip :......... trace id: ------location: en_US {http.status=200, Content-Type=application/json;charset=UTF-8}

6/28/19 4:08:52.952 PM INFO 2019-06-28 12:08:52,952 -------[[-------_rrfi.zip].throttling-task.01] LoggerMessageProcessor  BEFORE: IP_address: null API_name:-------server ip: -----trace id: ------ location: en_US
0 Karma
Highlighted

Re: extracting response status time

SplunkTrust
SplunkTrust

Where is the httpresponsetime field in those events?
Do you want to do the extraction at index time or search time?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: extracting response status time

New Member

i want to extract the duration of the the response from the beginning to the end event log as "HTTPSTATUSRESPONSE" so, i did not extract the httpstatusresponse yet .but i have to substract 9:05:26-4:08:52, to get the duration.

0 Karma
Highlighted

Re: extracting response status time

SplunkTrust
SplunkTrust

Assuming trace id is unique for a transaction and is extracted as trace_id, try this query:

index = foo | stats earliest(time) as start, latest(time) as end, values(http.status) as httpstatus, value(serverip) as serverip by traceid | eval httpresponsetime = tostring(end - start, "duration")

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma
Highlighted

Re: extracting response status time

New Member

Thank you for your best answer . so, i want to create this httpstatustime as a field and use it for another search like to get the MIN(httpresponsetime ) , MAX(httpresponsetime ) and median(httpresponsetime ) for each api and for each month?

0 Karma