hello
I use the search below
| inputlookup host.csv
| lookup PanaBatteryStatus.csv "Hostname00" as host OUTPUT CycleCount00
| where CycleCount00 > 200
| stats count as NbHostHealthInf85
| appendcols
[| inputlookup host.csv
| stats count as NbIndHost]
| eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85)
**| table NbHostHealthSup85 NbHostHealthInf85**
Now I want to do a pie chart on NbHostHealthSup85 NbHostHealthInf85 results but it doesnt works
could you help me please??
@jip31
Try this
Add | transpose
after your search.
Sample Search:
| makeresults | eval NbHostHealthSup85=100, NbHostHealthInf85=50 | table NbHostHealthSup85 NbHostHealthInf85 | transpose
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/transpose
Try this:
| inputlookup host.csv
| lookup PanaBatteryStatus.csv "Hostname00" as host OUTPUT CycleCount00
| where CycleCount00 > 200
| stats count as NbHostHealthInf85
| appendcols
[| inputlookup host.csv
| stats count as NbIndHost]
| eval NbHostHealthSup85 = (NbIndHost - NbHostHealthInf85)
| foreach NbHostHealthSup85 NbHostHealthInf85
[ eval <<FIELD>> = round(100 * <<FIELD>> / NbIndHost) ]
| table NbHostHealthSup85 NbHostHealthInf85
| untable foo name value
| fields - foo
@jip31
Try this
Add | transpose
after your search.
Sample Search:
| makeresults | eval NbHostHealthSup85=100, NbHostHealthInf85=50 | table NbHostHealthSup85 NbHostHealthInf85 | transpose
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/transpose
thanks
I didnt know this funtion!!!!!