Splunk Search

How can I show the total count as well as completed count?

akshaypillai
Engager

If I have to show that 8 out of 10 tickets have been closed how can I best show this? I need to show the total count as well as completed count

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This should get you started. You'll likely need to change the eval expression to whatever indicates a closed ticket.

<your base search for all tickets> | stats count(eval(status=Closed)) as closed, count as total | eval "Percentage Closed"=(closed*100)/total | rename closed as "Tickets Closed", total as "Total Tickets" | table "Tickets Closed" "Total Tickets" "Percentage Closed"
---
If this reply helps you, Karma would be appreciated.
0 Karma

elliotproebstel
Champion

One way to visually represent this would be to create a statistics table like this (with the percentage column optional, but nice to have):

Tickets Closed | Total Tickets | Percentage Closed
8              | 10            | 80%

Alternately, you could make a dashboard with two single items (or three, if you wanted the percentage), one for each value. And another way that would make sense to present that data would be a pie chart.

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...