Hello,
I have deployed splunk essentials for Application analytics under splunk 7.2.4(trial version)
I tried to configure the use case - Application Content / Identify Slow Web Pages which is part of the examples under the app.
Upon the ingestion of web server access logs, i ran the following command given under the example.
sourcetype="access_common"
| stats avg(response_time) as art by uri_path
| eval "Average Response Time (ms)" = round(art,2)
| sort -"Average Response Time (ms)"
| table uri_path "Average Response Time (ms)"
I'm unable to see Average Response entries under statistics.
A sample Extract from logs below.
06/02/2019
23:58:59.000
10.150.19.125 - - [06/Feb/2019:23:58:59 +0530] "GET /itpam/StartAgent?processType=startAgent≺ocess=startAgentpam.agent.httpscompatible=false&AGENT_STARTUP_VERSION=1&DeprecatedComms=true&requestType=launchagent HTTP/1.1" 404 1097
host = source = localhost_access_log.2019-02-06.txt sourcetype = access_common
06/02/2019
23:57:30.000
10.150.19.125 - - [06/Feb/2019:23:57:30 +0530] "GET /itpam/StartAgent?processType=startAgent≺ocess=startAgentpam.agent.httpscompatible=false&AGENT_STARTUP_VERSION=1&DeprecatedComms=true&requestType=launchagent HTTP/1.1" 404 1097
host = * source = localhost_access_log.2019-02-06.txt sourcetype = access_common
@asm_coe
Can you please confirm response_time
coming in event? Just execute the below search.
sourcetype="access_common" | table _time response_time uri_path
If response_time
coming then try below search.
sourcetype="access_common"
| stats avg(response_time) as art by uri_path
| eval art = round(art,2)
| sort -art
| table uri_path art | rename art as "Average Response Time (ms)"
@kamlesh_vaghela - yes. seems like response_time is not part of the log events. Attached is the output for the command below.
I don't see any extractions for this field. yet i see the field -response time under the table with null values.
@asm_coe
Can you please confirm response_time
coming in event? Just execute the below search.
sourcetype="access_common" | table _time response_time uri_path
If response_time
coming then try below search.
sourcetype="access_common"
| stats avg(response_time) as art by uri_path
| eval art = round(art,2)
| sort -art
| table uri_path art | rename art as "Average Response Time (ms)"
@asm_coe
I think response_time
field is not coming with an event. Is this field coming via any extractions ??
Can you please share output from the below search?
sourcetype="access_common" | table _time response_time uri_path
@asm_coe
It seems response_time
not available in the event. Can you please whether any other field contains value of response_time
?
And one request: can you please reply me by adding a comment below my comment instead of adding new comment?? 🙂 🙂
@kamlesh_vaghela - To my understanding no other field contains value of response_time. Also i have confirmed the same with the apps team.
@asm_coe
Yeah. I think you got your answer, why "Average Response Time" doesn't have any value in search table. Kindly upvote my comment which is useful to you and accepts the answer to close this question.
Happy Splunking
@kamlesh_vaghela Sure, Thanks for your assistance.