Splunk Search

How do you setup a pie chart for success / failures?

sunnyt
New Member

Query details:
index=my_app processcreditcheck tmLogging (failure OR success)

Result needed:
][1]

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should have a field dedicated to success or failure. If you don't have an existing field, you can write a regular expression to capture the "success" and "failure" values. Once you have these values in a field, you can then do something like this

... | stats count by <FIELD_NAME>

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...