I am looking to get a ratio in something akin to the following method but this is throwing errors from Splunk ES:
eval(count(eval(if(action!="success",1,null())))/count(eval(if(action=="success",1,null()))))
Anyone have any suggestions as to what might be the problem?
Use this query as a reference to calculate ratio:
basesearch | stats count(eval(if(action!="success",1,null))) as count1 count(eval(if(action="success",1,null))) as count2 | eval ratio=round(count1/count2,2) | fields ratio
Let me know if it works!