Hi All,
I am looking for pie chart which number success & Error events in the search. Below are my 2 query's.
Query 1 :- host = servername sourcetype=file index=index_prod "ERROR" | stats count
Query 2 :- host = servername sourcetype=file index=index_prod "Success" | stats count 
Initially i though to extract the field, But the in the event "Error" & "Success" falls on different fields. Can some please suggestion an idea.
 
		
		
		
		
		
	
			
		
		
			
					
		Chart this as a pie:
host = servername sourcetype=file index=index_prod ("ERROR" OR "SUCCESS") | eval class = if(searchmatch("ERROR"), "ERROR", "SUCCESS") | stats count by class
Combining the two searches will also give you a performance boost 🙂
Note, I've assumed that events containing both ERROR and SUCCESS will only be counted as ERROR.
Thank you very much
 
		
		
		
		
		
	
			
		
		
			
					
		Chart this as a pie:
host = servername sourcetype=file index=index_prod ("ERROR" OR "SUCCESS") | eval class = if(searchmatch("ERROR"), "ERROR", "SUCCESS") | stats count by class
Combining the two searches will also give you a performance boost 🙂
Note, I've assumed that events containing both ERROR and SUCCESS will only be counted as ERROR.
