Hi Team,
I want to create a splunk dashboard with the avearge response time taken by the all the API's wich follow this condition.
Example:
I have below API's
/api/cvraman/book
/api/apj/book
/api/nehru/book
/api/cvraman/collections
/api/apj/collections
/api/indira/collections
/api/rahul/notes
/api/rajiv/notes
/api/modi/notes
Now i will check for the average of the API /api/*/book,/api/*/collections,/api/*/notes.
Dashboard should have only these response times in the chart /api/*/book,/api/*/collections,/api/*/notes. i tried the below query but the dashboard shows the combined average on all the three can someone please help on this
index=your_index (URI = /api/*/book OR URI = /api/*/collections OR /api/*/notes. ) |stats avg(duration) as avg_time
... View more