Getting Data In

To get data from different source types

xvxt006
Contributor

Hi,

I am trying to calculate conversion rate using number of orders/visits. Number of visits from one sourcetype and visits are from different source type. So i have used join command. But i am not getting any output

sourcetype=XXXXX | stats count(OrderTotal) as Orders | join append[search sourcetype=YYYYY | stats dc(SessionID) as visits] | eval CVR =(Orders/Visits)*100 | table CVR

When i take out table CVR i can see that the 2 stats output values separately. But i want to use those and calculate the CVR and just output that value alone. Any help is much appreciated.

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

Try this

sourcetype=XXXXX  or sourcetype=YYYYYY
| stats count(OrderTotal) as Orders dc(SessionID) as Visits
| eval CVR =(Orders/Visits)*100

OR this, which is less efficient usually

sourcetype=XXXXXX
| stats count(OrderTotal) as Orders
| appendcols [ search sourcetype=YYYYY
    | stats dc(SessionID) as Visits ]
| eval CVR =(Orders/Visits)*100

Also, note that you used "visits" in one spot, and "Visits" in another. Field names are case-sensitive!

HTH

View solution in original post

lguinn2
Legend

Try this

sourcetype=XXXXX  or sourcetype=YYYYYY
| stats count(OrderTotal) as Orders dc(SessionID) as Visits
| eval CVR =(Orders/Visits)*100

OR this, which is less efficient usually

sourcetype=XXXXXX
| stats count(OrderTotal) as Orders
| appendcols [ search sourcetype=YYYYY
    | stats dc(SessionID) as Visits ]
| eval CVR =(Orders/Visits)*100

Also, note that you used "visits" in one spot, and "Visits" in another. Field names are case-sensitive!

HTH

xvxt006
Contributor

I tried your first solution initially and may be i might have missed the case sensitivity. Thank you HTH it is working now.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...