I am trying to create a graph with the top 10 longest response times by host.
An example is:
200 0 0 78
Where the last set of numbers represents the time taken in milliseconds-
which is what I'm trying to extract to make my graph.
Hi @bryceweb22 ,
Did you have a chance to check out any answers? If it worked, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.
Thanks for posting!
Splunk's timechart
automatically does this;
index="foo" sourcetype="bar" | timechart limit=10 max(response) BY host