Deployment Architecture

Average latency per hour

tmarlette
Motivator

I am attempting to find out the average latency of my requests by ip, per hour, over a 24 hour period. I'm sure i'm making this far too complicated, but it's friday at 5pm. 😃

The search I'm using:

website=services* NOT hck=* | bucket _time span=60min | stats avg(time_taken) by clientip

this is returning a single value, so i would assume that splunk is averaging the values per hour, and giving that single value? any help is appreciated!

Tags (2)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Your search does not take the time information into account;

website=services* NOT hck=* | bucket _time span=60min | stats avg(time_taken) by clientip, _time

OR

website=services* NOT hck* | timechart span=1h avg(time_taken) by clientip

is more likely what you need, but with many IP's the graph may not be all that nice.

/K

View solution in original post

kristian_kolb
Ultra Champion

Your search does not take the time information into account;

website=services* NOT hck=* | bucket _time span=60min | stats avg(time_taken) by clientip, _time

OR

website=services* NOT hck* | timechart span=1h avg(time_taken) by clientip

is more likely what you need, but with many IP's the graph may not be all that nice.

/K

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...