Splunk Search

How do you calculate the difference between two specific values in the same field (%) then timechart span=1h for the past 24hrs

johnward4
Communicator

How do you calculate the difference between two specific values in the same field and return that value in a percent format? I then need to be able to timechart that percentage difference over time, for my example this would be

conversion rate % span 1h

I've seen a few eval calculation example but none that gave me the output I'm looking for

index=example event="Entered Site" OR event="Checkout"
| top event
| eval percent = round(percent, 2)
0 Karma
1 Solution

HiroshiSatoh
Champion

Is it like this?

 index=example event="Entered Site" OR event="Checkout"
 | timechart span=1h count(eval(event="Entered Site")) as Entered,count(eval(event="Checkout")) as Checkout
 | eval percent=round(Checkout/Entered,2)
 | table _time,percent

View solution in original post

0 Karma

johnward4
Communicator

alt text

@HiroshiSatoh I'm trying to essentially reproduce the graph below that I have in an application called Mixpanel. I've onboarded the data to Splunk and the field I'm looking to visualization is called "event". In the event there are values called "App Opened" and "Product Checkout Began". I would like to know how you can calculate the % of Product Checkout Began from the total of App Opened and then timechart that % over time. For Example what is my conversion rate % per hour.

0 Karma

HiroshiSatoh
Champion

The answer was corrected.

0 Karma

HiroshiSatoh
Champion

Is it like this?

 index=example event="Entered Site" OR event="Checkout"
 | timechart span=1h count(eval(event="Entered Site")) as Entered,count(eval(event="Checkout")) as Checkout
 | eval percent=round(Checkout/Entered,2)
 | table _time,percent
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...