<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I am want to group  together similar pattern of data , and plot a pie chart to see the percentage of it. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583918#M203346</link>
    <description>&lt;P&gt;Below is the query I am &amp;nbsp;trying to use to get the result but, its giving error &amp;nbsp;for eval statement. Could anyone please help me here.&lt;/P&gt;&lt;P&gt;index="application_name" | spath logger | search logger=" logging.transcation.filter "| spath event | search event = "responseActivity"| search requestURI IN (/login,/api/v1/user/profile,/api/v1/app/version,/api/v1/user/profile/pickey,/api/v1/home/reseller/*) | eval requestURI=case((requestURI="/api/v1/home/reseller/*"), "/api/v1/homepage")&lt;/P&gt;</description>
    <pubDate>Mon, 07 Feb 2022 11:00:15 GMT</pubDate>
    <dc:creator>anu1729</dc:creator>
    <dc:date>2022-02-07T11:00:15Z</dc:date>
    <item>
      <title>I am want to group  together similar pattern of data , and plot a pie chart to see the percentage of it.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583918#M203346</link>
      <description>&lt;P&gt;Below is the query I am &amp;nbsp;trying to use to get the result but, its giving error &amp;nbsp;for eval statement. Could anyone please help me here.&lt;/P&gt;&lt;P&gt;index="application_name" | spath logger | search logger=" logging.transcation.filter "| spath event | search event = "responseActivity"| search requestURI IN (/login,/api/v1/user/profile,/api/v1/app/version,/api/v1/user/profile/pickey,/api/v1/home/reseller/*) | eval requestURI=case((requestURI="/api/v1/home/reseller/*"), "/api/v1/homepage")&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 11:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583918#M203346</guid>
      <dc:creator>anu1729</dc:creator>
      <dc:date>2022-02-07T11:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: I am want to group  together similar pattern of data , and plot a pie chart to see the percentage of it.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583920#M203347</link>
      <description>&lt;P&gt;There is nothing wrong with the eval statement as you have shared it. Could there be a different eval statement in your query?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 11:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583920#M203347</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-07T11:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: I am want to group  together similar pattern of data , and plot a pie chart to see the percentage of it.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583922#M203348</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; no this is only eval command I using here .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 11:26:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-am-want-to-group-together-similar-pattern-of-data-and-plot-a/m-p/583922#M203348</guid>
      <dc:creator>anu1729</dc:creator>
      <dc:date>2022-02-07T11:26:06Z</dc:date>
    </item>
  </channel>
</rss>

