Getting Data In

To get data from different source types

xvxt006
Contributor

Hi,

I am trying to calculate conversion rate using number of orders/visits. Number of visits from one sourcetype and visits are from different source type. So i have used join command. But i am not getting any output

sourcetype=XXXXX | stats count(OrderTotal) as Orders | join append[search sourcetype=YYYYY | stats dc(SessionID) as visits] | eval CVR =(Orders/Visits)*100 | table CVR

When i take out table CVR i can see that the 2 stats output values separately. But i want to use those and calculate the CVR and just output that value alone. Any help is much appreciated.

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

Try this

sourcetype=XXXXX  or sourcetype=YYYYYY
| stats count(OrderTotal) as Orders dc(SessionID) as Visits
| eval CVR =(Orders/Visits)*100

OR this, which is less efficient usually

sourcetype=XXXXXX
| stats count(OrderTotal) as Orders
| appendcols [ search sourcetype=YYYYY
    | stats dc(SessionID) as Visits ]
| eval CVR =(Orders/Visits)*100

Also, note that you used "visits" in one spot, and "Visits" in another. Field names are case-sensitive!

HTH

View solution in original post

lguinn2
Legend

Try this

sourcetype=XXXXX  or sourcetype=YYYYYY
| stats count(OrderTotal) as Orders dc(SessionID) as Visits
| eval CVR =(Orders/Visits)*100

OR this, which is less efficient usually

sourcetype=XXXXXX
| stats count(OrderTotal) as Orders
| appendcols [ search sourcetype=YYYYY
    | stats dc(SessionID) as Visits ]
| eval CVR =(Orders/Visits)*100

Also, note that you used "visits" in one spot, and "Visits" in another. Field names are case-sensitive!

HTH

xvxt006
Contributor

I tried your first solution initially and may be i might have missed the case sensitivity. Thank you HTH it is working now.

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...