You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

实现大于运算的Splunk面板:查询耗时超500ms的API总数的语句

共享应用日志

2021-08-25T20:45:17.382Z level=info module=xyz pid=45 message="queryAPI, Execution Time(ms):,617.195517, pId:45" 
2021-08-25T20:45:17.382Z level=info module=xyz pid=45 message="queryAPI, Execution Time(ms):,231.195517, pId:45"

符合要求的Splunk查询语句

# 替换<数据源筛选条件>为你实际的索引、sourcetype或source配置,匹配对应日志
<数据源筛选条件> "queryAPI" "Execution Time(ms):"
# 从message字段提取API名称、执行耗时两个字段
| rex field=message "^(?<api_name>[^,]+), Execution Time\(ms\):,(?<exec_time>[0-9\.]+), pId.*$"
# 过滤出耗时超过500ms的日志
| where exec_time > 500
# 按API名称分组统计出现次数
| stats count as "Total occurrences" by api_name
# 重命名字段匹配要求的输出格式
| rename api_name as "Delayed API-Name"

使用说明

将语句开头的<数据源筛选条件>替换为你环境中对应日志的匹配规则后执行,即可得到要求的两列表格。针对你提供的样例日志,查询结果的Total occurrences字段值为1。

内容的提问来源于stack exchange,提问作者fregp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 06:27:04