Hello,i would like to compute the ratio of some specific fields in total event, for example, in IPS attack event log, i wanna get known with the ratio of scr_ip coming from the specific country in total attack event, it seems straightforward, but i don't know how to use search command.(that is to say the number of events by using src=xxx or src=xxx..., divided by the number of events non-using such condiction), Thanks!!
... | stats count(src=="xxx") as xxx_count, count as total_count | eval ratio = xxx_count/total_count
You would need to add eval with stats some thing like
,we will need add eval in stats something like:
| stats count(eval(rslt=="found")) as cache_hit, count as total_count | eval ratio=cache_hit/total_count
| stats count(eval(rslt=="found")) as cache_hit, count as total_count | eval ratio=cache_hit/total_count
... | stats count(src=="xxx") as xxx_count, count as total_count | eval ratio = xxx_count/total_count
thanks, i try it, but the syntax stats should be count(eval(src="xxx")) as xxx_count