Splunk Search

timechart for post for multiple web sites

riqbal47010
Path Finder

I have multiple web portals.

portal= www.xyz.com, www.abc.com
post_method = get | post

Now I want a timechart like values(post_method) by portal
then I want to use trellis option like for each portal there is seperate graph with number of get and post requests.

0 Karma
1 Solution

woodcock
Esteemed Legend

Like this:

index="YouShouldAlwaysSpecifyAnIdex" AND sourcetype="AndSourcetypeToo" AND portal IN("www.xyz.com", "www.abc.com")
| timechart count(eval(post_method=="get")) AS Gets count(eval(post_method=="post")) AS Posts BY portal

Then the trellis function be functional and you can just click on which split you like ( portal or post_method )

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

index="YouShouldAlwaysSpecifyAnIdex" AND sourcetype="AndSourcetypeToo" AND portal IN("www.xyz.com", "www.abc.com")
| timechart count(eval(post_method=="get")) AS Gets count(eval(post_method=="post")) AS Posts BY portal

Then the trellis function be functional and you can just click on which split you like ( portal or post_method )

0 Karma

riqbal47010
Path Finder

thanks

it is working now as expected.

Sukisen1981
Champion

you cant timechart strings, what you need is timechart acount of get or post..something like |timechart count by post_method. You of course can not have 2 fields in the by clause.suggest using stats instead something like
|bin span=1h _time|stats count by post_method,portal

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...