Splunk Search

How do I display ONLY percentages on a timechart?


I know how to include percent in timecharts, however, all the answers I see return the other values in the timechart as well with the percent, such as this.

| timechart span=1d c(eval(success="false")) AS err c AS tot | eval err_ratio_perc = round(err/tot*100,0)

How Can I ONLY show the err_ratio_perc on the timechart?

Tags (2)
0 Karma


Add ..| fields - err - totto the end

0 Karma