Splunk Search

Httpstatuscode success/failure

lucky
Explorer

Hi All,

I have 3 API's 

1. in first API the status are code 200 & 403 as a success reaming all status codes are failure 

2. in 2nd & 3rd API's only 200 is the success  remaining all codes are failure 

I need to show graph as a line chart with "Y" axis as success percentage " 0 to 100"

in X-axis need to show time 

I have to use below time chart command like...

|timechart span=5m eval(if(count>10, round(mean(status),2), 100)) as percentage by countryCode useother=false limit=100

 

please help on this 

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

You need to explain your data set in a data centric forum.  Assuming that you have a field named API with values "API1", "API2", etc., and a field named status with 200, 403, etc.  I think what you are looking for is

| eval success = if(API == "API1" AND status == "403" OR status == "200", 1, 0)
| bin span=5m _time
| stats count sum(success) as success by countryCode _time
| eval percentage = round(success * 100 / count, 2)
| timechart useother=false limit=100 span=5m values(percentage) as percentage by countryCode
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...