Splunk Search

How do i get a % of page hits off the total users who accessed a set of pages.

abhijitd
New Member
index=app sourcetype=accesslog uri="some uri" user!="-"  (context="display" OR context="pages") earliest=-7d | rex field=page ^"(?<spacekey_or_action>\S+)(\/|\?|spaceKey\=|draftId\=|pageId\=|key\=)|(?<pid_or_sk>[0-9|a-z|A-Z|\+\%\-\:\(\)\.]{1,})|\&(?<article>\S+)" max_match=0 | search spacekey_or_action="123" OR (spacekey_or_action="viewpage.action" AND pid_or_sk="123")
|  stats dc(user) as users by page 
|  sort -users
|  eventstats sum(users) as totalUsers

I get the display as :

  1. Page1 100 150
  2. Page2 50 150

Basically, my question is how do i get a % so Page 1 is 66% of total events and Page 2 is 33% of total events and so on

The base rex and this followup rex searches all pages for the content group 123.

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

@abhijitd ,

Just add this to your search

  | eval perc=round((users/totalUsers)*100,2)
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

abhijitd
New Member

Thanks! this worked.

0 Karma

renjith_nair
Legend

@abhijitd ,

Just add this to your search

  | eval perc=round((users/totalUsers)*100,2)
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...