Hi all,
I am new to splunk
Following is the information:
Column1 Column2 column3
first Success
first Incomplete
First Timeout
I want the above information like
Column1 successcount Fail count
first 1 2
Note:Here Fail count is Incomplete and Timeout
Can any one help on this how to form a qeury to get the above output
Thanks
@uppukumar,
Try,
"your base search "
| stats count(eval(Column2 ="Success")) as SuccessCount,count(eval(Column2 !="Success")) as FailedCount by Column1
You may change the condition for FailedCount based on your criteria
Hi @uppukumar
Try like
your query..| stats count(eval(Coloumn2="Success")) as "Success count" count(eval(Coloumn2="Incomplete" OR Coloumn2="Timeout")) as "Fail count" by Coloumn1