Archive
Highlighted

How do I perform math against two searches?

New Member

I have two searches that use the same index and each return a numerical total, differing only in the period of time of the data they look at. How would I perform math on the search results for example adding or calculating percentages?

0 Karma
Highlighted

Re: How do I perform math against two searches?

Champion

maybe, could you write the 2 queries please..

0 Karma
Highlighted

Re: How do I perform math against two searches?

New Member

index=data NOT ID="" earliest=-1d@d latest=-0d@d | regex name!="[a-z]."| dedup id | stats count

index=data NOT ID="" earliest=-0d@d latest=now | regex name!="[a-z]."| dedup id | stats count

0 Karma
Highlighted

Re: How do I perform math against two searches?

Champion
| makeresults
| fields - _time
| eval Total1=[search index=data NOT ID="" earliest=-1d@d latest=-0d@d | regex name!="[a-z]."| dedup id | stats count | return $count] 
| eval Total2=[search index=data NOT ID="" earliest=-0d@d latest=now | regex name!="[a-z]."| dedup id | stats count | return $count]
| eval FullTotal=Total1+Total2 | eval percentage=((Total1/FullTotal)*100)

View solution in original post

Highlighted

Re: How do I perform math against two searches?

New Member

Thank you, that works great!

0 Karma