Reporting

How to add percentage to Column Report?

JHFRDANALYSIS
New Member

Hi. I'm brand new to splunk.  I've created a table report that shows counts of columns:

Time (Hour)

Result: Good

Result: Bad

Result: Ugly

After the Index and source type, my query has     |chart count over _time span=hour by data.result

What do I need to add to query to calculate the Total of Good, Bad, Ugly and then use that to add a column with the percentage of Total Result to the table.  Appreciate your help.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This requirement is not clear enough.

Do you want the counts converted to percentages of total per hour or do you want additional columns for each result with percentages of the total per hour or do you want percentages of the grand total or do you want an additional row with the totals for each result or something else?

Please can you provide a mock-up of what you would like to see?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...