Splunk Search

How to get results for how often each alarm type occurs in percentage

marenastrauss
New Member

I have uploaded alarm logs into Splunk. I would like to be able to show results for how often each alarm type occurs in percentage.

For example, the percentage of total alarms that Alarm 1 makes up and the percentage that Alarm 2 takes up, to see which alarm occurs more.

Thank you!

0 Karma
1 Solution

renjith_nair
Legend

@marenastrauss ,

In general , below should work

"your search"|stats count by alarm_type|eventstats sum(count) as total | eval perc=round((count/total)*100)
Happy Splunking!

View solution in original post

0 Karma

renjith_nair
Legend

@marenastrauss ,

In general , below should work

"your search"|stats count by alarm_type|eventstats sum(count) as total | eval perc=round((count/total)*100)
Happy Splunking!
0 Karma

marenastrauss
New Member

That worked! I had to do it without round though because then it only gives back 0's. Thank you!

0 Karma

Sukisen1981
Champion

hi @marenastrauss
Then please accept the answer of @renjith.nair

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...