Splunk Search

How can I show the total count as well as completed count?

akshaypillai
Engager

If I have to show that 8 out of 10 tickets have been closed how can I best show this? I need to show the total count as well as completed count

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This should get you started. You'll likely need to change the eval expression to whatever indicates a closed ticket.

<your base search for all tickets> | stats count(eval(status=Closed)) as closed, count as total | eval "Percentage Closed"=(closed*100)/total | rename closed as "Tickets Closed", total as "Total Tickets" | table "Tickets Closed" "Total Tickets" "Percentage Closed"
---
If this reply helps you, Karma would be appreciated.
0 Karma

elliotproebstel
Champion

One way to visually represent this would be to create a statistics table like this (with the percentage column optional, but nice to have):

Tickets Closed | Total Tickets | Percentage Closed
8              | 10            | 80%

Alternately, you could make a dashboard with two single items (or three, if you wanted the percentage), one for each value. And another way that would make sense to present that data would be a pie chart.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...