Splunk Search

How to compare 2 Search's percentage results?

EBVanguard
Engager

Hey Team, 
I am trying to generate a search which returns a complete set of results from today and then compares it with a search whereby the results only came in between 4-5pm. 
I then want to work out the precentage of results which came in between 4-5pm.

So far I have:

EBVanguard_0-1663332163135.png

 

With the **** being where I think I need to timeframe search?

Thanks!

Labels (3)
0 Karma
1 Solution

maciep
Champion

So maybe just this then?

| stats count(eval(date_hour="16")) as ycount, totalcount

 

View solution in original post

0 Karma

maciep
Champion

So maybe just this then?

| stats count(eval(date_hour="16")) as ycount, totalcount

 

0 Karma
Get Updates on the Splunk Community!

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...