Reporting

how to calculate availability percentage within the last hour?

dhavamanis
Builder

Can you please tell us, how to calculate availability percentage using Splunk query for the below case in last one hour,

(total_event - total_5*_status_code_event)/total_event = average_availability.

Sample base query :

total_event = index="myindex"
total_5*_status_code_event = index="myindex" status="5**"

Once we get the results, need to assign this value in speedometer graph as report.

0 Karma
1 Solution

strive
Influencer

To calculate percentage try this

some search terms | eval Count5xx=if(status like "5%",1,0)  | stats sum(Count5xx) as Count5xx count(status) as Total | eval AvailablePercentage=(Total - Count5xx)*100/Total

View solution in original post

strive
Influencer

To calculate percentage try this

some search terms | eval Count5xx=if(status like "5%",1,0)  | stats sum(Count5xx) as Count5xx count(status) as Total | eval AvailablePercentage=(Total - Count5xx)*100/Total
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...