Splunk Search

How to chart the percentage of errors per server over time?

fc_splk
Engager

Hi,

Considering a set of servers, I would like to plot the percentage of errors for each server over time. I am trying to create one view with a line for each server.

I managed to get a statistics table with the following query and tried to pipe something like "xyseries _time, host, percent", but this doesnt work.

 ... |  chart count(eval(responseCode like "2%")) AS success, count(eval(NOT responseCode like "2%"))  AS failure by host | addtotals fieldname=Total success, failure | eval Errors_Percentage=round(failure*100/Total)

I tried with a timechart as well, but then didn't manage to add the percentage field for each span/host.

Thanks!

0 Karma
1 Solution

sundareshr
Legend

This, I think, should give you the chart you're looking for

... | eval httpstatus=if(status>299, "Failed", "Success") | bin _time as t span=1d | eval time_host=t."@".host | chart count over time_host by httpstatus | addtotals | eval Perc=Failed/Total*100 | rex field=time_host "(?<Time>\d+)@(?<Host>\w+)" | table Time Host Perc | fieldformat Time=strftime(Time, "%Y/%m/%d") | xyseries Time Host Perc

View solution in original post

sundareshr
Legend

This, I think, should give you the chart you're looking for

... | eval httpstatus=if(status>299, "Failed", "Success") | bin _time as t span=1d | eval time_host=t."@".host | chart count over time_host by httpstatus | addtotals | eval Perc=Failed/Total*100 | rex field=time_host "(?<Time>\d+)@(?<Host>\w+)" | table Time Host Perc | fieldformat Time=strftime(Time, "%Y/%m/%d") | xyseries Time Host Perc
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...