<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a linechart with Percentages via Timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502412#M139865</link>
    <description>&lt;P&gt;This worked perfectly. Thanks for preventing me from pulling more hair out!&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2019 16:27:08 GMT</pubDate>
    <dc:creator>giventofly08</dc:creator>
    <dc:date>2019-10-16T16:27:08Z</dc:date>
    <item>
      <title>How to create a linechart with Percentages via Timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502410#M139863</link>
      <description>&lt;P&gt;I'm looking to create a timechart that will show the percentage of success versus failure of 6 different fields over the past 6 months (broken up by each month, so I believe it's span=1mon). The goal is to have the percentages in a linechart of each respective Operating System over the past 6 months.&lt;/P&gt;

&lt;P&gt;My current syntax will display the percentage of the current month of these 6 fields, but I cannot figure out the timechart syntax to have it show the previous 6 months.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search query
| dedup comp_id check_id
| eval state_Win10=if(name="Windows 10",if((state="passed"), "Passed", "Failed"), null())
| eval state_Win7=if(name="Windows 7",if((state="passed"), "Passed", "Failed"), null())
| eval state_Win2008=if(name="Windows 2008",if((state="passed"), "Passed", "Failed"), null())
| eval state_Win2012=if(name="Windows 2012",if((state="passed"), "Passed", "Failed"), null())
| eval state_RHEL6=if(name="RHEL 6",if((state="passed"), "Passed", "Failed"), null())
| eval state_RHEL7=if(name="RHEL 7",if((state="passed"), "Passed", "Failed"), null())
| stats count(eval(state_Win10="Passed")) AS Win10Passed, count(eval(state_Win10="Failed")) AS Win10Failed, count(eval(state_Win7="Passed")) AS Win7Passed, count(eval(state_Win7="Failed")) AS Win7Failed, count(eval(state_Win2008="Passed")) AS Win2008Passed, count(eval(state_Win2008="Failed")) AS Win2008Failed, count(eval(state_Win2012="Passed")) AS Win2012Passed, count(eval(state_Win2012="Failed")) AS Win2012Failed, count(eval(state_RHEL6="Passed")) AS RHEL6Passed, count(eval(state_RHEL6="Failed")) AS RHEL6Failed, count(eval(state_RHEL7="Passed")) AS RHEL7Passed, count(eval(state_RHEL7="Failed")) AS RHEL7Failed 
| eval Win10PC=round(100-((Win10Failed/(Win10Passed+Win10Failed))*100),1), Win7PC=round(100-((Win7Failed/(Win7Passed+Win7Failed))*100),1)
| eval Win2008PC=round(100-((Win2008Failed/(Win2008Passed+Win2008Failed))*100),1)
| eval Win2012PC=round(100-((Win2012Failed/(Win2012Passed+Win2012Failed))*100),1)
| eval RHEL6PC=round(100-((RHEL6Failed/(RHEL6Passed+RHEL6Failed))*100),1)
| eval RHEL7PC=round(100-((RHEL7Failed/(RHEL7Passed+RHEL7Failed))*100),1)
| fields Win10PC Win7PC Win2008PC Win2012PC RHEL6PC RHEL7PC
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thank you for the assistance or advice to help me solve this.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 13:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502410#M139863</guid>
      <dc:creator>giventofly08</dc:creator>
      <dc:date>2019-10-16T13:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a linechart with Percentages via Timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502411#M139864</link>
      <description>&lt;P&gt;instead of stats use timechart and in last add _time in fields. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search query&lt;BR /&gt;
 | dedup comp_id check_id&lt;BR /&gt;
 | eval state_Win10=if(name="Windows 10",if((state="passed"), "Passed", "Failed"), null())&lt;BR /&gt;
 | eval state_Win7=if(name="Windows 7",if((state="passed"), "Passed", "Failed"), null())&lt;BR /&gt;
 | eval state_Win2008=if(name="Windows 2008",if((state="passed"), "Passed", "Failed"), null())&lt;BR /&gt;
 | eval state_Win2012=if(name="Windows 2012",if((state="passed"), "Passed", "Failed"), null())&lt;BR /&gt;
 | eval state_RHEL6=if(name="RHEL 6",if((state="passed"), "Passed", "Failed"), null())&lt;BR /&gt;
 | eval state_RHEL7=if(name="RHEL 7",if((state="passed"), "Passed", "Failed"), null())&lt;BR /&gt;
 | timechart count(eval(state_Win10="Passed")) AS Win10Passed, count(eval(state_Win10="Failed")) AS Win10Failed, count(eval(state_Win7="Passed")) AS Win7Passed, count(eval(state_Win7="Failed")) AS Win7Failed, count(eval(state_Win2008="Passed")) AS Win2008Passed, count(eval(state_Win2008="Failed")) AS Win2008Failed, count(eval(state_Win2012="Passed")) AS Win2012Passed, count(eval(state_Win2012="Failed")) AS Win2012Failed, count(eval(state_RHEL6="Passed")) AS RHEL6Passed, count(eval(state_RHEL6="Failed")) AS RHEL6Failed, count(eval(state_RHEL7="Passed")) AS RHEL7Passed, count(eval(state_RHEL7="Failed")) AS RHEL7Failed &lt;BR /&gt;
 | eval Win10PC=round(100-((Win10Failed/(Win10Passed+Win10Failed))*100),1), Win7PC=round(100-((Win7Failed/(Win7Passed+Win7Failed))*100),1)&lt;BR /&gt;
 | eval Win2008PC=round(100-((Win2008Failed/(Win2008Passed+Win2008Failed))*100),1)&lt;BR /&gt;
 | eval Win2012PC=round(100-((Win2012Failed/(Win2012Passed+Win2012Failed))*100),1)&lt;BR /&gt;
 | eval RHEL6PC=round(100-((RHEL6Failed/(RHEL6Passed+RHEL6Failed))*100),1)&lt;BR /&gt;
 | eval RHEL7PC=round(100-((RHEL7Failed/(RHEL7Passed+RHEL7Failed))*100),1)&lt;BR /&gt;
 | fields _time Win10PC Win7PC Win2008PC Win2012PC RHEL6PC RHEL7PC&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 16:11:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502411#M139864</guid>
      <dc:creator>Anantha123</dc:creator>
      <dc:date>2019-10-16T16:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a linechart with Percentages via Timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502412#M139865</link>
      <description>&lt;P&gt;This worked perfectly. Thanks for preventing me from pulling more hair out!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 16:27:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-linechart-with-Percentages-via-Timechart/m-p/502412#M139865</guid>
      <dc:creator>giventofly08</dc:creator>
      <dc:date>2019-10-16T16:27:08Z</dc:date>
    </item>
  </channel>
</rss>

