<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to achieve stats count eval chart? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623492#M216744</link>
    <description>&lt;P&gt;Have you tried removing the unwanted fields?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;BASIC_SEARCH&amp;gt; | chart count by path_template, http_status_code 
| addtotals fieldname=total
| foreach 2* 3* 4* 5* [ eval 
  "percent_&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=round(100*'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'/total,2),
  "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=0 , '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;', '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'." 
  (".'percent_&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'."%)")] 
| fields - percent_* total 2* 3* 4*&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 06 Dec 2022 21:36:43 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-12-06T21:36:43Z</dc:date>
    <item>
      <title>How to achieve stats count eval chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623481#M216741</link>
      <description>&lt;P&gt;Dear Splunk community:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following search query:&lt;/P&gt;
&lt;P&gt;&amp;lt;BASIC_SEARCH&amp;gt; | chart count by path_template, http_status_code | addtotals fieldname=total&lt;BR /&gt;| foreach 2* 3* 4* 5* [ eval "percent_&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=round(100*'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'/total,2),&lt;BR /&gt;"&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=0 , '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;', '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'." (".'percent_&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'."%)")] | fields - percent_* total&lt;/P&gt;
&lt;P&gt;Attached is a sample of the current output based on the above search.&lt;/P&gt;
&lt;P&gt;I am trying to do the same thing except only show the 500, 502,503 columns (but still do all the calculation based on the total count of everything). How do i change the above search to achieve this?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Daryoush&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 19:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623481#M216741</guid>
      <dc:creator>djoobbani</dc:creator>
      <dc:date>2022-12-06T19:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to achieve stats count eval chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623492#M216744</link>
      <description>&lt;P&gt;Have you tried removing the unwanted fields?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;BASIC_SEARCH&amp;gt; | chart count by path_template, http_status_code 
| addtotals fieldname=total
| foreach 2* 3* 4* 5* [ eval 
  "percent_&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=round(100*'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'/total,2),
  "&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;"=if('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'=0 , '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;', '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'." 
  (".'percent_&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'."%)")] 
| fields - percent_* total 2* 3* 4*&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 06 Dec 2022 21:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623492#M216744</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-06T21:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to achieve stats count eval chart?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623503#M216749</link>
      <description>&lt;P&gt;Yes this works, thank u very much!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 22:10:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-achieve-stats-count-eval-chart/m-p/623503#M216749</guid>
      <dc:creator>djoobbani</dc:creator>
      <dc:date>2022-12-06T22:10:45Z</dc:date>
    </item>
  </channel>
</rss>

