Hello Splunkers,
I am new to Splunk and I'm having a hard time generating what should be a simple report. I'd like to produce a pie chart that shows browser usage by major browser (IE, Firefox, Chrome, Safari, etc.).
I started with the following mess of a query, but it doesn't give me "chartable" results:
sourcetype="access" useragent!="-"
AND useragent!="Apache*"
AND useragent!="Load-weight*"
AND useragent!="Java*"
AND useragent!="Jakarta Commons-HttpClient*"
AND useragent!="Mozilla/4.0 en"
| table SessionCookie, useragent
| dedup SessionCookie
| stats
count(eval(match(useragent, "Firefox"))) as "Firefox",
count(eval(match(useragent, "Chrome"))) as "Chrome",
count(eval(match(useragent, "Safari"))) as "Safari",
count(eval(match(useragent, "MSIE"))) as "IE",
count(eval(NOT match(useragent, "Chrome|Firefox|Safari|MSIE"))) as "Other"
Does anyone have an example query that could get me to my pie chart?
Thanks,
Mark