I have success events in sourcetype XYZ. Failure events in sourcetype ABC. I want to show failure count as a percentage of Success count. How can I do this?
This should get you started.
sourcetype=XYZ OR sourcetype=ABC | stats count as Total, count(eval(sourcetype="ABC")) as Fail | eval PercentFail=(Fail/Total)*100
Hi pathuris,
you can search over both sourcetypes and count each events and compare them with this per day search example:
base search here sourcetype=XYZ OR sourcetype=ABC
| bucket _time span=1d
| stats count(eval(events=="success")) AS success_count count(eval(events=="failure")) AS failure_count
| eval perc=failure_count*100/(failure_count + success_count)
This assumes you have a field called events
which contains either success
or failure
as status.
Hope this helps ...
cheers, MuS