Hello.
I have an index of Akamai logs forwarded to Splunk, and I'm trying to query for origin latency, which is a json object (netPerf.netOriginLatency) in these logs.
How can I query through CLI to return the value of this object for a minute for example (average latency per minute)? First, I tried to query just for the object value (without time filters) with 'spath' as shown below, but it didn't work:
./splunk search 'index=akamai message.fwdHost=someservice.mydomain.com | spath=netPerf.netOriginLatency'
How could I do that? Is it possible?
Best,