<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Query to get Error rate percentage in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673315#M230554</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;there are already quite many examples about this (or at least with event data). You could find those with search "&lt;A href="https://www.google.com/search?q=site%3Asplunk.com+calculate+error+rate&amp;amp;client=safari&amp;amp;sca_esv=595895911&amp;amp;rls=en&amp;amp;ei=wbuXZe3qMLKGwPAPh7ug4A0&amp;amp;udm=&amp;amp;ved=0ahUKEwitz8el6MWDAxUyAxAIHYcdCNwQ4dUDCA8&amp;amp;uact=5&amp;amp;oq=site%3Asplunk.com+calculate+error+rate&amp;amp;gs_lp=Egxnd3Mtd2l6LXNlcnAiJHNpdGU6c3BsdW5rLmNvbSBjYWxjdWxhdGUgZXJyb3IgcmF0ZUjAJFDhBFjnHHABeACQAQCYAUmgAeMIqgECMjC4AQPIAQD4AQHiAwQYASBBiAYB&amp;amp;sclient=gws-wiz-serp#ip=1" target="_blank"&gt;site:splunk.com calculate error rate&lt;/A&gt;". You must just modify those to work with metric index if you have stored that data into those.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2024 08:57:40 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-01-05T08:57:40Z</dc:date>
    <item>
      <title>Splunk Query to get Error rate percentage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673313#M230553</link>
      <description>&lt;P&gt;I want to have a query that can show me the percentage of error rate in the "AccountDetailsController" service of my application. We have the metrics data coming in from splunk so If that has to be used or however we can do this. Please help&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 08:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673313#M230553</guid>
      <dc:creator>sonal</dc:creator>
      <dc:date>2024-01-05T08:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to get Error rate percentage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673315#M230554</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;there are already quite many examples about this (or at least with event data). You could find those with search "&lt;A href="https://www.google.com/search?q=site%3Asplunk.com+calculate+error+rate&amp;amp;client=safari&amp;amp;sca_esv=595895911&amp;amp;rls=en&amp;amp;ei=wbuXZe3qMLKGwPAPh7ug4A0&amp;amp;udm=&amp;amp;ved=0ahUKEwitz8el6MWDAxUyAxAIHYcdCNwQ4dUDCA8&amp;amp;uact=5&amp;amp;oq=site%3Asplunk.com+calculate+error+rate&amp;amp;gs_lp=Egxnd3Mtd2l6LXNlcnAiJHNpdGU6c3BsdW5rLmNvbSBjYWxjdWxhdGUgZXJyb3IgcmF0ZUjAJFDhBFjnHHABeACQAQCYAUmgAeMIqgECMjC4AQPIAQD4AQHiAwQYASBBiAYB&amp;amp;sclient=gws-wiz-serp#ip=1" target="_blank"&gt;site:splunk.com calculate error rate&lt;/A&gt;". You must just modify those to work with metric index if you have stored that data into those.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 08:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673315#M230554</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-01-05T08:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query to get Error rate percentage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673320#M230555</link>
      <description>&lt;P&gt;But from where to find the field that are to be used in the query. I cannot find it anywhere. Only this information is present in "builtin:service.errors.server.rate " metrics :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;1/5/24&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5:10:00.000 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" title="" href="https://itsi-thehartford.splunkcloud.com/en-US/app/itsi/search?q=%7C%20mpreview%20index%3Ditsi_im_metrics%20%7C%20search%20entity.service.name%20%3D%20%22AccountDetailsControllerImpl%22%20metric_name%3Abuiltin%3Aservice.errors.server.rate%20!%3D%20%220%22%20source.name%20%3D%20%22DT_Prod_SaaS%22&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;earliest=0&amp;amp;latest=&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1704445837.12899469#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;MessageDeduplicationId&lt;/SPAN&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;aggregation&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;avg&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;entity.service.id&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;SERVICE-xxxxx&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;entity.service.name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;AccountDetailsControllerImpl&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;metric_name:builtin:service.errors.server.rate&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;3.8461538461538463&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;resolution&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;1m&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;source.name&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;DT_Prod_SaaS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;unit&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;Percent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 09:15:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-to-get-Error-rate-percentage/m-p/673320#M230555</guid>
      <dc:creator>sonal</dc:creator>
      <dc:date>2024-01-05T09:15:11Z</dc:date>
    </item>
  </channel>
</rss>

