Hi Splunk Experts,
I am very new to Splunk and need some help to resolve my problem.
I have a dataset that comprises many fields with key fields are timestamp, user, region, location, delay.
I need to divide delay into two bands; one band is for users meeting <500 ms threshold and and another band for those above 500 ms.
I would like to create two outputs: a table and a bar chart that shows me:
Many thanks for help..
This should give you the desired results:
<your_base_search> | stats count(eval(delay<500)) as users_below_500, count(*) as total_users, perc90(delay) as 90percentile by region, location | eval users_below_500_percentage=round(users_below_500/total*100,2) | table region location users_below_500 users_below_500_percentage 90percentile