Splunk Search

How do you calculate the difference between two specific values in the same field (%) then timechart span=1h for the past 24hrs

johnward4
Communicator

How do you calculate the difference between two specific values in the same field and return that value in a percent format? I then need to be able to timechart that percentage difference over time, for my example this would be

conversion rate % span 1h

I've seen a few eval calculation example but none that gave me the output I'm looking for

index=example event="Entered Site" OR event="Checkout"
| top event
| eval percent = round(percent, 2)
0 Karma
1 Solution

HiroshiSatoh
Champion

Is it like this?

 index=example event="Entered Site" OR event="Checkout"
 | timechart span=1h count(eval(event="Entered Site")) as Entered,count(eval(event="Checkout")) as Checkout
 | eval percent=round(Checkout/Entered,2)
 | table _time,percent

View solution in original post

0 Karma

johnward4
Communicator

alt text

@HiroshiSatoh I'm trying to essentially reproduce the graph below that I have in an application called Mixpanel. I've onboarded the data to Splunk and the field I'm looking to visualization is called "event". In the event there are values called "App Opened" and "Product Checkout Began". I would like to know how you can calculate the % of Product Checkout Began from the total of App Opened and then timechart that % over time. For Example what is my conversion rate % per hour.

0 Karma

HiroshiSatoh
Champion

The answer was corrected.

0 Karma

HiroshiSatoh
Champion

Is it like this?

 index=example event="Entered Site" OR event="Checkout"
 | timechart span=1h count(eval(event="Entered Site")) as Entered,count(eval(event="Checkout")) as Checkout
 | eval percent=round(Checkout/Entered,2)
 | table _time,percent
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...