Splunk Search
Highlighted

How can I compare the ratio of errors to 10 minutes ago for all our app_pools?

Builder

I would like to get a ratio of errors by app_pool, and then compare it to 5, 10, 1hr ago?

tag=java | 
stats count as "Events" by app_pool | 
appendcols [search 
tag=java tag=problem |
stats count as "Problems" by app_pool]

I am thinking a running summary index counting errors and counting events by app_pool, then a search which compares things after the fact? Is there a better way to do this?

0 Karma
Highlighted

Re: How can I compare the ratio of errors to 10 minutes ago for all our app_pools?

Legend

Try this

tag=java earliest=@d | timechart span=1h count as Events count(eval(tag=problem)) as Problems | eval ratio=round(Problems/Events, 2)
0 Karma
Highlighted

Re: How can I compare the ratio of errors to 10 minutes ago for all our app_pools?

Builder

Hmm, the evals there don't seem to work. Returning nothing.

0 Karma
Highlighted

Re: How can I compare the ratio of errors to 10 minutes ago for all our app_pools?

Legend

Sorry, problem needs to be in quotes. count(eval(tag="problem"))

0 Karma
Highlighted

Re: How can I compare the ratio of errors to 10 minutes ago for all our app_pools?

Esteemed Legend

You need the timewrap app:

https://splunkbase.splunk.com/app/1645/

0 Karma