Splunk Search

Counting percentage with completion and not completed status

k31453
Explorer

Hi, I have following data:

k31453_0-1619137770961.png


And I am trying to create SPL which gets me following result:

k31453_1-1619137816420.png


I tried eventstate and stats command but not getting where i wanted.

Labels (2)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

 

Hi @k31453 

Following query would help!

index="<your_index>" sourcetype="<sourcetype>" 
| stats count(user) as "Total_Customer", count(eval(all_flag_updated=="yes")) as "updated_flag" , count(eval(all_flag_updated=="no")) as "not_updated_flag" by region 
| eval updated_flag_perc = (updated_flag/Total_Customer) * 100, no_updated_flag_perc = (not_updated_flag/Total_Customer) * 100 
| table Total_Customer updated_flag not_updated_flag updated_flag_perc no_updated_flag_perc region

-------------------------------------------------

An upvote would be appreciated if it helps!

 

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!