In the manual we have:
sourcetype=access_* action=purchase
[search sourcetype=access_* action=purchase | top limit=1 clientip | table clientip] |
stats count, values(product_id) as product_id by clientip |
rename count AS "How much did he buy?", product_id AS "What did he buy?", clientip AS "VIP Customer"
If I need know de percentage of each product_id? What can I do?
Will this work for you?
sourcetype=access_* action=purchase
[search sourcetype=access_* action=purchase | top limit=1 clientip | fields clientip] |
stats count by clientip product_id | eventstats sum(count) as totalPurchased |
eval Percentage = round(count*100/totalPurchased,1) |
table clientip product_id count Percentage |
rename count AS "How much did he buy?", product_id AS "What did he buy?", clientip AS "VIP Customer"