Hi I have a Splunk search as follows:
My search | table host_name, last_seen_in_24hours
which displays the result as follows
Now I'm trying to see the percentage of YES's and NO's in a pie chart.
Just add this to end of your search and select pie chart visualization
your current search | stats count by last_seen_in_24hours
@pavanae, in case your hosts can have duplicate data for last_seen_in_24_hours, you would need to dedup or get latest value per host
<YourBaseSearch>
| stats last(last_seen_in_24_hours) as last_seen_in_24_hours by host
| stats count by last_seen_in_24_hours
Or
<YourBaseSearch>
| dedup host
| stats count by last_seen_in_24_hours
Just add this to end of your search and select pie chart visualization
your current search | stats count by last_seen_in_24hours