Splunk Search

How to edit my stats count search to chart a percentage trend over time?

sidekix24
Path Finder

Hi,

I have the search below that displays an availability percentage for me, but now I'm looking to time chart that percentage to show a trend of the availability percentage over time. I'm thinking that the issue I'm having is that once you use count, that does a count over the selected time so it wraps up everything into that one percentage.

| stats count(eval(Login_Status)) AS Total count(eval(Login_Status=302 AND Recruiter_Status=200 AND QuickSearch_Status=200)) AS Success | eval Division=Success/Total | eval Percent=round ((Division)*100,2) | eval Final=Percent + "%" | table Percent

Anyone have any suggestions or ideas to try?

Thanks

0 Karma
1 Solution

vasildavid
Path Finder

Use buckets and break your stats down by _time.

| bucket _time span=5m 
  | stats count(eval(Login_Status)) AS Total, count(eval(Login_Status=302 AND Recruiter_Status=200 AND QuickSearch_Status=200)) AS Success by _time 
  | eval Division=Success/Total 
  | eval Percent=round ((Division)*100,2) 
  | eval Final=Percent + "%" 
  | table _time, Percent

View solution in original post

0 Karma

vasildavid
Path Finder

Use buckets and break your stats down by _time.

| bucket _time span=5m 
  | stats count(eval(Login_Status)) AS Total, count(eval(Login_Status=302 AND Recruiter_Status=200 AND QuickSearch_Status=200)) AS Success by _time 
  | eval Division=Success/Total 
  | eval Percent=round ((Division)*100,2) 
  | eval Final=Percent + "%" 
  | table _time, Percent
0 Karma

sidekix24
Path Finder

Thanks vasildavid!!! That did the trick

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...