Splunk Search

2D table to display test results

pm18
New Member

Hi,

I want to create a table to display the results(pass rate) of some test results we send to splunk.
We send the following fields: flow, stage, protocol and success. Each flow can have any number of stages, and there can be any number of protocols. Success is a boolean that stores if the test has passed or not.

Ideally, the test results should look like this:

           protocol1      protocol2     protocol3    ...

flow1 stage1 100% 90%
stage2 5% ...
stage3
flow2 stage1
stage2

flow3 stage1
stage2
stage3
stage4
...

Any ideas on how to build? Thanks

Tags (2)
0 Karma

lguinn2
Legend

Try this

yoursearchhere
| stats count(success="T") as success count as total by flow stage protocol
| eval successPercent = round(success*100/total, 1)
| eval flow_and_stage = flow + " " + stage
| chart sum(successPercent) by flow_and_stage protocol

HTH

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...