calculate percentage from two sums?
Comment by dang on dang's answer
Thanks! I was able to get this to work. The mixed case was accidental, and thanks for pointing it out.
Fri, 18 Feb 2011 06:53:03 GMT
dang
<p>are 'attempts' and 'successes' fields that are being extracted from each event? </p>
<p>Is the difference in casing intentional? In one place you say 'successes', but in the search it's in title case. (beware that field names in splunk are case-sensitive)</p>
<p>Assuming the events in <code><your search></code> are returning fields called 'attempts' and 'successes', the following will give you a timechart where the y-axis is showing the percentage of successes for each time-bucket in the chart. </p>
<pre><code><your search> | timechart sum(attempts) as totalAttempts sum(successes) as totalSuccesses
| eval percent=totalSuccesses*100/totalAttempts | fields - totalAttempts totalSuccesses
Fri, 18 Feb 2011 06:41:58 GMT
sideview