Skip to main content


Splunk Lantern

Long-term website performance trends

You might need to track the response time for performance of a website when doing the following:


In order to execute this procedure in your environment, the following data, services, or apps are required:


Gradual performance degradations introduced by regular software releases, increasing site load, or underprovisioned hardware often goes undetected without regular monitoring. Using the site homepage as a baseline, you want to perform long-term trending of site performance to identify problems. Additionally, you want a visualization to validate that a major production change hasn't inadvertently affected site performance.

To optimize the search shown below, you should specify an index and a time range. In addition, this sample search uses Splunk Add-on for Apache Web Server. You can replace this source with any other web server data used in your organization. 

  1. Verify you deployed a web server add-on to the search heads, so that the needed tags and fields are defined. For more information, see About installing Splunk add-ons.
  2. Choose one or two global or critical pages on your site to filter on. Alternatively, if you're leveraging an up/down detector like Pingdom, you can filter on that.
  3. Run the following search: 
tag=web site=<URL of critical page> uri_path IN ("/?*", "/index.*", "/home*", "/login*") response_time=*
|timechart span=1h perc95(response_time) AS perc95_response_time avg(response_time) AS avg_response_time

Search explanation

The table provides an explanation of what each part of this search achieves. You can adjust this query based on the specifics of your environment.

Splunk Search Explanation


Search for events that are tagged as web events.

site=<URL of site>

Search only the site you want to use as a baseline. For example,

uri_path IN ("/?*", "/index.*", "/home*", "/login*") 

Return uri_path values that have a partial match to any of the strings shown.


Search for results with any response time.

|timechart span=1h perc95(response_time) AS perc95_response_time avg(response_time) AS avg_response_time

Graph the average and 95th percentile response times for each uri_path in 1-hour time increments.


A column chart in stack mode allows you to easily visualize the trends in response times for the filtered uri_paths. You should investigate periodic rises and falls in your response times to determine the cause. 

A common next step is to compare this month to last month and have the two timecharts on the same dashboard. You can adjust the current month and previous month timeframes if your business needs a longer or shorter time period to view and compare.

  • Was this article helpful?