Splunk Search

Need to create a search thatshows both success percentage and failure count in dual axis combo chart.

vijaysubramania
Path Finder

Hi,

I need to write a search that shows both the success percentage and failure count in a dual axis combo chart.

I am able to do it independently, but unable to do it in a combo chart, which is only showing the trend for the last 7 days (y-axis) while failure events will give the overall count for the day (x-axis).

"requestMethod=POST AND "/customerentitlementsservice/v1/ces/account*" responseStatus"

Success trend:

|dedup requestId 
|eval FailureCount=if((responseStatus != 200) OR like(Status,"%,%"),1,0) 
|bin _time span=1d 
|stats  count as Total, sum(FailureCount) as Fail by _time 
|eval successrate=Round(((Total-Fail)*100)/Total,2 )
|eval Date =strftime(_time, "%m/%d/%y") 
|chart values(successrate)  AS Successrate% by Date
0 Karma

maityayan1996
Path Finder

Use this below query which will give you the successrate along with sum(failcount) per day basis in a single chart. Please accept the answer once you resolve the issue. Thanks

|dedup requestId
|eval FailureCount=if((Status!=200) OR like(Status,"%,%"),1,0)
|bin _time span=1d
|stats count as Total, sum(FailureCount) as Fail by _time
|eval successrate=Round(((Total-Fail)*100)/Total,2 )
|eval Date =strftime(_time, "%m/%d/%y")
| stats values(Fail) as Fail , values(successrate) as successrate by _time

0 Karma

vijaysubramania
Path Finder

Thanks maityayan. This works,

I did it in other way around but only problem is printing in 6 decimals

|stats count(eval(responseStatus=200)) as Success, count as Total by _time
|eval Percent=round((Success/Total)*100,2), Failure=Total-Success |eval Date =strftime(_time, "%m/%d/%y")
|timechart avg(Percent) AS Successrate%, avg(Failure) AS Failed-Session-Count

94.680000 617.000000

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...