Getting Data In

To get data from different source types

xvxt006
Contributor

Hi,

I am trying to calculate conversion rate using number of orders/visits. Number of visits from one sourcetype and visits are from different source type. So i have used join command. But i am not getting any output

sourcetype=XXXXX | stats count(OrderTotal) as Orders | join append[search sourcetype=YYYYY | stats dc(SessionID) as visits] | eval CVR =(Orders/Visits)*100 | table CVR

When i take out table CVR i can see that the 2 stats output values separately. But i want to use those and calculate the CVR and just output that value alone. Any help is much appreciated.

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

Try this

sourcetype=XXXXX  or sourcetype=YYYYYY
| stats count(OrderTotal) as Orders dc(SessionID) as Visits
| eval CVR =(Orders/Visits)*100

OR this, which is less efficient usually

sourcetype=XXXXXX
| stats count(OrderTotal) as Orders
| appendcols [ search sourcetype=YYYYY
    | stats dc(SessionID) as Visits ]
| eval CVR =(Orders/Visits)*100

Also, note that you used "visits" in one spot, and "Visits" in another. Field names are case-sensitive!

HTH

View solution in original post

lguinn2
Legend

Try this

sourcetype=XXXXX  or sourcetype=YYYYYY
| stats count(OrderTotal) as Orders dc(SessionID) as Visits
| eval CVR =(Orders/Visits)*100

OR this, which is less efficient usually

sourcetype=XXXXXX
| stats count(OrderTotal) as Orders
| appendcols [ search sourcetype=YYYYY
    | stats dc(SessionID) as Visits ]
| eval CVR =(Orders/Visits)*100

Also, note that you used "visits" in one spot, and "Visits" in another. Field names are case-sensitive!

HTH

xvxt006
Contributor

I tried your first solution initially and may be i might have missed the case sensitivity. Thank you HTH it is working now.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...