<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to graph SLA conformance? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218510#M13563</link>
    <description>&lt;P&gt;Thx for clarifying..&lt;/P&gt;</description>
    <pubDate>Sat, 12 Nov 2016 20:51:26 GMT</pubDate>
    <dc:creator>kabSplunk</dc:creator>
    <dc:date>2016-11-12T20:51:26Z</dc:date>
    <item>
      <title>How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218506#M13559</link>
      <description>&lt;P&gt;I have a sourcetype that is an extract from a hardware fault call logging system. One of the columns (called ‘Conformance’) has a value that tells you if the call was resolved within the timeframe of a 'service level agreement' (SLA). A value of 1 means the call met the SLA, a value of 0 means the call failed the SLA. However, there is another column called ‘Override’ and if there is any text in that column, then that indicates that the SLA failure was overridden and the call met the SLA. With me so far?!&lt;/P&gt;

&lt;P&gt;What I need to do is identify the number of calls that met the SLA:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search NOT Override="*" AND Conformance=1 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;... then identify the number of calls that failed the SLA, and were then overridden:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search Override="*" AND Conformance=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;... then I need to identify the number of calls that failed the SLA:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search NOT Override="*" AND Conformance=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Finally, I need to take all the calls that met the SLA first time, add that number to the calls that met the SLA having been ‘overridden’, and then display that as one value in a pie chart, along with the calls that failed the SLA. It will be a pie chart with one very big segment (SLA achieved), and one very small one (SLA failed).&lt;/P&gt;

&lt;P&gt;If you can help, I would be very grateful, as I have a deadline to meet in 2 days time!&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2016 16:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218506#M13559</guid>
      <dc:creator>talbotrs</dc:creator>
      <dc:date>2016-11-12T16:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218507#M13560</link>
      <description>&lt;P&gt;Hi @talbotrs, please try this below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base query to get Conformance and Override events
| eval slaStats=case(((Conformance=1 AND Override!="*") OR (Override="*" AND Conformance=0)), "SLA achieved", (Override!="*" AND Conformance=0), "SLA failed", 1=1, "Other" )
| stats count by slaStats
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now in the Visualization choose pie chart and it should show up like you expected.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Updated the brackets as per comment&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2016 19:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218507#M13560</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-11-12T19:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218508#M13561</link>
      <description>&lt;P&gt;What is 1=1 doing in this?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2016 20:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218508#M13561</guid>
      <dc:creator>kabSplunk</dc:creator>
      <dc:date>2016-11-12T20:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218509#M13562</link>
      <description>&lt;P&gt;case default&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2016 20:39:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218509#M13562</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-11-12T20:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218510#M13563</link>
      <description>&lt;P&gt;Thx for clarifying..&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2016 20:51:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218510#M13563</guid>
      <dc:creator>kabSplunk</dc:creator>
      <dc:date>2016-11-12T20:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218511#M13564</link>
      <description>&lt;P&gt;Hi, thank-you so much for your reply ... unfortunately, I could not get this query to work, and I think the reason is that one of the closing brackets is in the wrong place. I tried a number of changes, but none of them worked. However, you did confirm what I thought, which was that the ‘eval’ command is the way to address this particular requirement. I looked at the training material that I got from the ‘Searching and Reporting with Splunk’ training course, and used one of the examples to produce the following query (the ‘NOT Customer’ parts of the query are to exclude 3 customers where the SLA data is not present in the ‘crspcalls’ sourcetype):&lt;/P&gt;

&lt;P&gt;(Bizarrely,  the asterisk symbol won't display properly here, so I've used the word 'asterisk' instead)&lt;/P&gt;

&lt;P&gt;sourcetype=crspcalls NOT Customer="CustomerA" AND NOT Customer="CustomerB" AND NOT Customer="CustomerC" &lt;BR /&gt;
| stats &lt;BR /&gt;
count(eval(Conformance="1" AND Override!="asterisk")) as Met, &lt;BR /&gt;
count(eval(Conformance="0" AND Override="asterisk")) as Overridden,&lt;BR /&gt;
count(eval(Conformance="0" AND Override!="asterisk")) as Failed&lt;/P&gt;

&lt;P&gt;That query ran without producing any errors, but I could see that the results were not accurate at all. So the query results  were 3 columns on the ‘Statistics’ tab (Met, Overridden and Failed), but the results were completely inaccurate. If I changed the 2 instances of&lt;BR /&gt;
AND Override!="asterisk"&lt;BR /&gt;
to &lt;BR /&gt;
AND NOT Override="asterisk"&lt;BR /&gt;
the query produced different results, but again, completely inaccurate results.&lt;/P&gt;

&lt;P&gt;I realised that the issue was with the searching the Override field using the asterisk symbol, as if I listed all the possible values that exist in the Override field, as in the following example, the results were accurate.&lt;/P&gt;

&lt;P&gt;sourcetype=crspcalls NOT Customer="CustomerA" AND NOT Customer="CustomerB" AND NOT Customer="CustomerC" &lt;BR /&gt;
| stats &lt;BR /&gt;
count(eval(Conformance="1" AND NOT Override="NF"&lt;BR /&gt;
AND NOT Override="HU"&lt;BR /&gt;
AND NOT Override="NF-CHARGE"&lt;BR /&gt;
)) as Met, &lt;BR /&gt;
count(eval(Conformance="0" AND Override="NF" &lt;BR /&gt;
OR Override="HU"&lt;BR /&gt;
OR Override="NF-CHARGE"&lt;BR /&gt;
)) as Overridden,&lt;BR /&gt;
count(eval(Conformance="0" AND NOT Override="NF"&lt;BR /&gt;
AND NOT Override="HU"&lt;BR /&gt;
AND NOT Override="NF-CHARGE"&lt;BR /&gt;
)) as Failed&lt;/P&gt;

&lt;P&gt;I’ve only listed 3 of the possible values that exist in the Override field, but there are in fact 36 possible values. As you can imagine, the query with all 36 possible values listed 3 times is a bit of a monster query!&lt;/P&gt;

&lt;P&gt;Can you suggest what the problems is with the asterisk symbol, or can you see where the problem is with the misplaced closing bracket in your original suggestion? &lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2016 12:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218511#M13564</guid>
      <dc:creator>talbotrs</dc:creator>
      <dc:date>2016-11-14T12:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218512#M13565</link>
      <description>&lt;P&gt;@talbotrs - When you are posting sample code, you need to wrap your text in a "code sample". That is why the asterisks in your code are not properly rendering. Use the "code sample" button located in the toolbar, to the right of the Blockquote (") button.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2016 16:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218512#M13565</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-11-14T16:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to graph SLA conformance?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218513#M13566</link>
      <description>&lt;P&gt;Can you please try to see if &lt;CODE&gt;isnull&lt;/CODE&gt; works for your case, where you change the &lt;CODE&gt;| eval slaStats=case(((Conformance=1 AND Override!="*") OR (Override="*" AND Conformance=0)), "SLA achieved", (Override!="*" AND Conformance=0), "SLA failed", 1=1, "Other" )&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;as follows:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| eval slaStats=case(((Conformance=1 AND isnull(Override)) OR (NOT isnull(Override) AND Conformance=0)), "SLA achieved", (isnull(Override) AND Conformance=0), "SLA failed", 1=1, "Other" )&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I have updated the brackets in the answer. Apologies for having missed it earlier.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 03:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-graph-SLA-conformance/m-p/218513#M13566</guid>
      <dc:creator>gokadroid</dc:creator>
      <dc:date>2016-11-15T03:07:51Z</dc:date>
    </item>
  </channel>
</rss>

