Hi, I need help in creating one query.
There is one field "Operator" having multiple values like airphone,bphone,vsphone etc.
The query should return the total count of each (airphone,bphone,vsphone etc.) per minute along with failed percentage of each.
Also if that query could specify for which location there are maximum failure of each.
Working search:
source="logfilename" host="test" index="splunkdata" earliest=-10m
| eventstats count(eval(Logon_message="for")) as Successful by Operator
| eventstats count(eval(Logon_message="error")) as Failed by Operator
| eventstats count(eval(Logon_message="*")) as Total by Operator
| eval perc_error = ((Failed)/(Total)*100)
| stats values(Successful) as "Total Successful" values(Failed) as "Total Failed" values(Total) as "Total Logins" values(perc_error) as Percentage by Operator
Working search:
source="logfilename" host="test" index="splunkdata" earliest=-10m
| eventstats count(eval(Logon_message="for")) as Successful by Operator
| eventstats count(eval(Logon_message="error")) as Failed by Operator
| eventstats count(eval(Logon_message="*")) as Total by Operator
| eval perc_error = ((Failed)/(Total)*100)
| stats values(Successful) as "Total Successful" values(Failed) as "Total Failed" values(Total) as "Total Logins" values(perc_error) as Percentage by Operator
hello there,
with plenty of respect, it seems like you are almost asking us to do your homework for you.
how would you tell if its failed or succeeded?
what have you tried so far? share your search please as well as a sample data.
Thanks adonio.
I was missing in a point to use eventstats for the same.
I have achieved the desired results.
Glad you're able to find a resolution on your own. Please post the search/solution that has worked for you as an answer and accept the same to close this question. This will help other splunkers with similar issues to know the working solution.