Hi -
I have been not having much luck creating what I need.
I am looking for the best way to display the percentages of a field's values.
For instance
index=foo |stats count by IP
and the results might be
IP | count | percentage |
10.10.10.1 | 12 | .60 |
10.10.10.5 | 1 | .05 |
10.10.10.8 | 7 | .35 |
I am looking for a clean and efficient way to calculate the percentages, in this case, for the occurrence of an IP for a given time in a search. I will be using it in an ML density function model, so any other suggestion appreciated as well.
Please let me know if you have a suggestion.
Thank you
Might be an easier way to do it but I'd try, for example
<your search>
| stats count by IP
| eventstats sum(count) as total
| eval percentage=count/total