Splunk Search

How to get percentage from stats count on http statuses?

xvxt006
Contributor

Hi,

I would like to get stats by http status and also i would like to add percentage column. when i use top it gives by uri or some other field which i don't want.

Right now output looks like this. But i need to add percentage.
status count
200 557374
301 151
302 61
400 33
404 542
405 24
500 6541

Tags (2)
1 Solution

somesoni2
Revered Legend

Try something like this

your base search | stats count by status | eventstats sum(count) as perc | eval perc=round(count*100/perc,2)

View solution in original post

somesoni2
Revered Legend

Try something like this

your base search | stats count by status | eventstats sum(count) as perc | eval perc=round(count*100/perc,2)
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...