I am a Newb at Splunk, so please bear with me if this is straight forward or has been answered previously. I have successfully used your Splunk>Answers on a number of occasions, but I am struggling with how to phrase this search.
SITUATION: I work in an assembly facility. I am currently calculating the number of good parts per completed device using:
| stats count(eval(PartStatus=1)) AS "GOOD PARTS"
A correctly assembled device will contain a set number of GOOD PARTS (let's use "N"). I would like to count the number of devices based on "N". By doing this I will have the following:
"GOOD DEVICES" - the number of devices that have "N" number of GOOD PARTS
"BAD DEVICES" - the number of devices that do NOT have "N" number of GOOD PARTS
QUESTION: How do I count the number of GOOD DEVICES and the number of BAD DEVICES, each of which are based on a value derived from a previous count?
... View more