Splunk Search

## How to add percentage on statistic field?

Contributor

Hello,

My search: index=test sourcetype=traffic | stats sum(A) as A sum(B) as B sum(C) as C sum(D) as D | transpose

A,B,C,D are number, but when I use top command to show percentage, it calculates the number as name, so the result turns out to be 1, which means 25% each.
How do I add percentage of each column on statistic fields?

サーチ文: index=test sourcetype=traffic | stats sum(A) as A sum(B) as B sum(C) as C sum(D) as D | transpose

※A,B,C,Dはネットワークトラフィックを表す数字です。

Tags (4)
1 Solution
Motivator

おそらく、、、こんな感じではないでしょうか。

``````... | stats sum(A) as A ... | transpose
| rename column as name, "row 1" as count
| eventstats sum(count) as total
| eval percent=100*(count/total)
| fields - total
``````
Motivator

おそらく、、、こんな感じではないでしょうか。

``````... | stats sum(A) as A ... | transpose
| rename column as name, "row 1" as count
| eventstats sum(count) as total
| eval percent=100*(count/total)
| fields - total
``````
Contributor

ありがとうございます！

Get Updates on the Splunk Community!

#### Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...