{"id":6287,"date":"2017-05-11T09:26:23","date_gmt":"2017-05-11T14:26:23","guid":{"rendered":"http:\/\/appcrawler.com\/wordpress\/?p=6287"},"modified":"2017-05-11T09:26:23","modified_gmt":"2017-05-11T14:26:23","slug":"splunk-query-to-group-apache-sessions-by-minute","status":"publish","type":"post","link":"http:\/\/appcrawler.com\/wordpress\/2017\/05\/11\/splunk-query-to-group-apache-sessions-by-minute\/","title":{"rendered":"Splunk query to group Apache sessions by minute"},"content":{"rendered":"<p>The 15th field of our Apache log is the application server session ID.  We truncate the _time field to minute, and get a distinct count of sessions in each minute.  The number is 14 below because the source array is zero based.<\/p>\n<pre>\r\nhost=strlpecomweb* sourcetype=access_combined \r\n   | eval temp=split(_raw,\\\"\\t\\\") \r\n   | eval sess=mvindex(temp,14) \r\n   | bucket span=1m _time \r\n   | stats dc(sess) as sesscount by _time\r\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>The 15th field of our Apache log is the application server session ID. We truncate the _time field to minute, and get a distinct count of sessions in each minute. The number is 14 below because the source array is&hellip;<\/p>\n<p class=\"more-link-p\"><a class=\"more-link\" href=\"http:\/\/appcrawler.com\/wordpress\/2017\/05\/11\/splunk-query-to-group-apache-sessions-by-minute\/\">Read more &rarr;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false,"footnotes":""},"categories":[81],"tags":[],"_links":{"self":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts\/6287"}],"collection":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/comments?post=6287"}],"version-history":[{"count":3,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts\/6287\/revisions"}],"predecessor-version":[{"id":6291,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts\/6287\/revisions\/6291"}],"wp:attachment":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/media?parent=6287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/categories?post=6287"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/tags?post=6287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}