Can you please tell us, how to calculate availability percentage using Splunk query for the below case in last one hour,
(total_event - total_5*_status_code_event)/total_event = average_availability.
Sample base query :
total_event = index="myindex"
total_5*_status_code_event = index="myindex" status="5**"
Once we get the results, need to assign this value in speedometer graph as report.
To calculate percentage try this
some search terms | eval Count5xx=if(status like "5%",1,0) | stats sum(Count5xx) as Count5xx count(status) as Total | eval AvailablePercentage=(Total - Count5xx)*100/Total
To calculate percentage try this
some search terms | eval Count5xx=if(status like "5%",1,0) | stats sum(Count5xx) as Count5xx count(status) as Total | eval AvailablePercentage=(Total - Count5xx)*100/Total