I'm performing a very simple search:
type="Workflow model" | top 20 org
My problem is, the number of events does not correspond to the listed percentage. Example: The total number of events is 1 503 929 and there are 649726 events where org=x. This should give a percentage of approximately 43,2. However, Splunk displays the percentage as 44,782654.
Is this merely a rounding problem, or am I missing something?
Top command you posted will return percentage for events where field org is present. Use this and see if percentage matches.
type="Workflow model" org=* | top 20 org
Top command you posted will return percentage for events where field org is present. Use this and see if percentage matches.
type="Workflow model" org=* | top 20 org
Of course, that's it. Thanks!