Hi splunkers,
I thought it would be easier, but now I need to ask you for help.
I need to make a simple tart chart with the percent of an IP Address and the percent of all other together as "Other".
How can I group all values in a single value "other" but leaving out just the value I want to analyze?
Thanks!
Hi @JohnnyMnemonic
are you expecting output like below , then please use pie chart
have you condsied using cidrmatch?.
I am currently using this query but it seems a bit hard for the search head:
index=logs sourcetype=more_logs dest_ip=*
| eval address=IF(LIKE(dest_ip, "0.0.0.0"), "YES", "OTHER")
| stats count by address
Hi @JohnnyMnemonic
are you expecting output like below , then please use pie chart
have you condsied using cidrmatch?.