Knowledge Management

Splunk saving P98 into summary index as NOT a number

silversson
New Member

Hello gents and ladies,

I am trying to write response time P98 to summary index.
I do:
| stats p98(response_time)
and get a nice result of 0.040sec. But if I do this:
| sistats p98(response_time)
and get psrsvd_nx_response_time
0e-03:191;2e-03:17;3e-03:23;5e-03:1;1.0e-02:1;1.3e-02:2;1.4e-02:1;1.5e-02:2;1.7e-02:1;1.8e-02:12;1.9e-02:2;2.1e-02:1;2.2e-02:3;2.3e-02:1;2.5e-02:3;3e-02:1;5e-02:2;6e-02:1;

Why does SPLUNK not save the number in summary indexer like I want it to and instead saves that odd hash?

Appreciate any help. Thanks in advance.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

sistats saves preliminary results to the summary index, stats gives you human-readable numbers. Use stats to retrieve data from summary indexes that has been calculated using sistats.

martin_mueller
SplunkTrust
SplunkTrust

It's not an unusable hash, it's a preliminary result. In order to pre-compute preliminary results for things like percentile values you need to store more than a simple number, you need to store a distribution of values.

stats knows how to deal with these preliminary results and should do the right thing.

0 Karma

silversson
New Member

Thanks for that. This is true but when I save the odd hash into the summary index I can not read it.
If I use:
| sistats avg(response_time)
| sistats min(response_time)
| sistats max(response_time)

it saves a usable number into the summary index. Only the p98 saves the odd unusable hash I have above.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...