Splunk Search

2D table to display test results

pm18
New Member

Hi,

I want to create a table to display the results(pass rate) of some test results we send to splunk.
We send the following fields: flow, stage, protocol and success. Each flow can have any number of stages, and there can be any number of protocols. Success is a boolean that stores if the test has passed or not.

Ideally, the test results should look like this:

           protocol1      protocol2     protocol3    ...

flow1 stage1 100% 90%
stage2 5% ...
stage3
flow2 stage1
stage2

flow3 stage1
stage2
stage3
stage4
...

Any ideas on how to build? Thanks

Tags (2)
0 Karma

lguinn2
Legend

Try this

yoursearchhere
| stats count(success="T") as success count as total by flow stage protocol
| eval successPercent = round(success*100/total, 1)
| eval flow_and_stage = flow + " " + stage
| chart sum(successPercent) by flow_and_stage protocol

HTH

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...