Looking for assistance in adding a percentage to an existing chart result. I have the following Splunk search that is able to chart the maximum value found of ValueA and ValueB and chart by hosts. ValueA is the maximum count found (lets say total number of objects). ValueB is the maximum observed usage of ValueA. I do not use a bin or time reference directly in the search, rather using Splunk's pre-build time reference on-demand (Example , "last 24 hours" when executing the search)
index=indextype sourcetype=sourcetype "search_string" | chart max(valueA) max(valueB) by host
Hi @chrisludke
Try the following to eval a percentage, note that Ive named the field on the stats so it is easier to reference.
| stats max(valueA) as max_valueA, max(valueB) as max_valueB by host
| eval percentage = round((max_valueB / max_valueA) * 100, 2)
| table host, max_valueA, max_valueB, percentage
Here is a sample query:
| makeresults
| eval valueA=1000, valueB=932, host="Test"
| stats max(valueA) as max_valueA, max(valueB) as max_valueB by host
| eval percentage = round((max_valueB / max_valueA) * 100, 2)
| table host, max_valueA, max_valueB, percentage
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Worked perfectly. Exactly what I needed. Thanks so much for your quick response!
Hi @chrisludke
Try the following to eval a percentage, note that Ive named the field on the stats so it is easier to reference.
| stats max(valueA) as max_valueA, max(valueB) as max_valueB by host
| eval percentage = round((max_valueB / max_valueA) * 100, 2)
| table host, max_valueA, max_valueB, percentage
Here is a sample query:
| makeresults
| eval valueA=1000, valueB=932, host="Test"
| stats max(valueA) as max_valueA, max(valueB) as max_valueB by host
| eval percentage = round((max_valueB / max_valueA) * 100, 2)
| table host, max_valueA, max_valueB, percentage
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing