Splunk Search

Calculate percent

C37996518
Explorer

index=Myindex sourcetype=mine mysearch    | eval Result=if(Apple="1","Bad","Good")
| stats count by Result

 

The search above gives me the correct count of events where Apple="1"

eg

Result                                                 Count

Bad                                                       5 

Good                                                  12392

 

How do I express the stats as a  single value in percentage ie  Bad/Good?

How do I alert  if the percentage  > .02%

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

NB: and on a slight technical note to ITWhispers comments, if you're looking for bad as a % of total rather than of goodNB, then

 

| eval percent=100*Bad/(Bad+Good)

 

View solution in original post

C37996518
Explorer

@C37996518 wrote:

index=Myindex sourcetype=mine mysearch    | eval Result=if(Apple="1","Bad","Good")
| stats count by Result

 

The search above gives me the correct count of events where Apple="1"

eg

Result                                                 Count

Bad                                                       5 

Good                                                  12392

 

How do I express the stats as a  single value in percentage ie  Bad/Good?

How do I alert  if the percentage  > .02%


Thanks to both. Perfect!!

0 Karma

bowesmana
SplunkTrust
SplunkTrust

NB: and on a slight technical note to ITWhispers comments, if you're looking for bad as a % of total rather than of goodNB, then

 

| eval percent=100*Bad/(Bad+Good)

 

ITWhisperer
SplunkTrust
SplunkTrust
index=Myindex sourcetype=mine mysearch
| eval Bad=if(Apple="1",1,0)
| eval Good=if(Apple="1",0,1)
| stats sum(Bad) as Bad sum(Good) as Good
| eval percent=100*Bad/Good
| where percent>0.02

The last line is for the alert so that you only get results when the percentage is greater than 0.02

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...