Dear Splunk community:
I have the following search query:
<BASIC_SEARCH> | chart count by path_template, http_status_code | addtotals fieldname=total
| foreach 2* 3* 4* 5* [ eval "percent_<<FIELD>>"=round(100*'<<FIELD>>'/total,2),
"<<FIELD>>"=if('<<FIELD>>'=0 , '<<FIELD>>', '<<FIELD>>'." (".'percent_<<FIELD>>'."%)")] | fields - percent_* total
Attached is a sample of the current output based on the above search.
I am trying to do the same thing except only show the 500, 502,503 columns (but still do all the calculation based on the total count of everything). How do i change the above search to achieve this?
Thanks,
Daryoush
Have you tried removing the unwanted fields?
<BASIC_SEARCH> | chart count by path_template, http_status_code
| addtotals fieldname=total
| foreach 2* 3* 4* 5* [ eval
"percent_<<FIELD>>"=round(100*'<<FIELD>>'/total,2),
"<<FIELD>>"=if('<<FIELD>>'=0 , '<<FIELD>>', '<<FIELD>>'."
(".'percent_<<FIELD>>'."%)")]
| fields - percent_* total 2* 3* 4*
Have you tried removing the unwanted fields?
<BASIC_SEARCH> | chart count by path_template, http_status_code
| addtotals fieldname=total
| foreach 2* 3* 4* 5* [ eval
"percent_<<FIELD>>"=round(100*'<<FIELD>>'/total,2),
"<<FIELD>>"=if('<<FIELD>>'=0 , '<<FIELD>>', '<<FIELD>>'."
(".'percent_<<FIELD>>'."%)")]
| fields - percent_* total 2* 3* 4*
Yes this works, thank u very much!