Dashboards & Visualizations

fetching the count based on field value

sahana
Engager

Hi 

I get a log in below format of JSON obj

message{

             Dashboard{

                             status: SUCCESS

                              operationName:gettingResult

}

In the above logs i get a value of SUCCESS/FAILURE for status. Now my requirement is to calculate a total,totalSuccess and totalFailure based on operationName. Tried the below query but it is not working out

 

 ......messgae.Dashboard.status=*| stats count as total,count(eval(messgae.Dashboard.status=SUCCESS)) as totalSuccess, count(eval(messgae.Dashboard.status=FAILURE)) as totalFailure by messgae.Dashboard.operationName

 

getting value for total but not for totaSuccess /totalFailure

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Is it simply a typo in the field name? Or not having quotes around SUCCESS and FAILURE?

0 Karma

sahana
Engager

It is simply a typo we don't have any quotes for success and failure

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried it with quotes around SUCCESS and FAILURE?

0 Karma

sahana
Engager

Yes I have tried it also not working

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...