How to do it...

Follow these steps to use a scatter chart to identify discrete requests by size and response time:

  1. Log in to your Splunk server.
  2. Select the default Search & Reporting application.
  3. Ensure that the time range picker is set to Last 24 hours, and type the following search into the Splunk search bar. Then, click on Search or hit Enter:
index=main sourcetype=access_combined | eval kb=bytes/1024  | table method kb response
  1. Splunk will return a tabulated list of the method, kb, and response fields for each event.
  2. Click on the Visualization tab and select Scatter Chart from the drop-down list of visualization types to see the data represented as a scatter plot chart. You should see the cluster of normal activity and then some discrete ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.