I want to create a chart of pie type. I define a field named "NbPAN". The values of this field are integers. With this field, I want to create a pie. In this chart, I want to have a part with the sum of the values of the field NbPAN which are upper than 1 and a part with the sum of the values of the field NbPAN which are equal at 1. But, actually, my search add the number of events where the condition is true and not the sum of the values of the field NbPAN with the true condition.
This is my search:
tag::source="TokenizerWatchdogSplunk"| stats sum(eval(NbPAN<2)) AS NBPANUNITAIRE, sum(eval(NbPAN>1)) AS NBPANMASSSE
My second problem is that I can't do my tie because I don't know how create my chart.
Thanks for your answer. With your search, it's the good sum that it does. Now, I'm not able to create a pie with a part NBPANUNITAIRE and a part NBPANMASSSE. It takes only the NbPANUNITAIRE values. I think that it's because there are two columns in my table and to do a pie we have to do only one column no????