Splunk Search

Group count percentage by key

xiangli9
Observer

We have 5 host and 3 on west 2 on east, and each of them take x% of request, the stats we have right now looks like:

host                |      percentage 

ip-1-west.    |        15

ip-2-west.    |.        15

ip-3-west.    |.         20

ip-4-east.     |.         20

ip-50-east   |.         30

Now I'm trying to group the percentage by east and west so I can have the statics like:

host      |      percentage 

west.    |         50

east.     |         50

 

Can someone help me with this?

Labels (3)
0 Karma

anilchaithu
Builder

@xiangli9 

try this

base search | rex field=host "^.*-(?P<host>\w+)$" | stats sum(percentage) as percentage by host

 

Hope this helps 

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...