Splunk Search

One field and multiple custom values and get percentages

pudanelilita
Explorer

Hi,
I need hep to create table, which shows multiple custom values / field count / %
example, how it need to look:

alt text

Tags (1)
0 Karma

Adrian_ftx
Path Finder

Hi pudanelilita,

Can you provide a sample of your data please?
We can't give you the expected result if we don't have sample of your data.

Best regards,
Adrian

0 Karma

pudanelilita
Explorer

Event:
2019-08-28T14:05:27.078+0000: 89492.967: [GC pause (G1 Evacuation Pause) (young), **0.0422004** secs]
[Parallel Time: 29.3 ms, GC Workers: 13]
[GC Worker Start (ms): Min: 89492967.4, Avg: 89492967.5, Max: 89492967.6, Diff: 0.3]
[Ext Root Scanning (ms): Min: 7.0, Avg: 8.0, Max: 14.8, Diff: 7.8, Sum: 104.5]
[Update RS (ms): Min: 1.4, Avg: 7.4, Max: 8.5, Diff: 7.1, Sum: 96.6]
[Processed Buffers: Min: 3, Avg: 21.3, Max: 49, Diff: 46, Sum: 277]
[Scan RS (ms): Min: 0.1, Avg: 0.3, Max: 0.4, Diff: 0.3, Sum: 3.4]
[Code Root Scanning (ms): Min: 0.0, Avg: 0.0, Max: 0.0, Diff: 0.0, Sum: 0.1]
[Object Copy (ms): Min: 12.3, Avg: 13.1, Max: 13.4, Diff: 1.1, Sum: 170.3]
[Termination (ms): Min: 0.0, Avg: 0.0, Max: 0.0, Diff: 0.0, Sum: 0.0]
[Termination Attempts: Min: 1, Avg: 1.0, Max: 1, Diff: 0, Sum: 13]
[GC Worker Other (ms): Min: 0.0, Avg: 0.1, Max: 0.2, Diff: 0.2, Sum: 1.8]
[GC Worker Total (ms): Min: 28.8, Avg: 29.0, Max: 29.2, Diff: 0.4, Sum: 376.7]
[GC Worker End (ms): Min: 89492996.4, Avg: 89492996.5, Max: 89492996.6, Diff: 0.2]
[Code Root Fixup: 0.0 ms]
[Code Root Purge: 0.0 ms]
[Clear CT: 0.9 ms]
[Other: 12.0 ms]
[Choose CSet: 0.0 ms]
[Ref Proc: 8.7 ms]
[Ref Enq: 0.2 ms]
[Redirty Cards: 0.4 ms]
[Humongous Register: 0.2 ms]
[Humongous Reclaim: 0.1 ms]
[Free CSet: 1.8 ms]
[Eden: 7540.0M(7540.0M)->0.0B(7440.0M) Survivors: 64.0M->112.0M Heap: 13.4G(15.0G)->6260.5M(15.0G)]
[Times: user=0.39 sys=0.01, real=0.04 secs]

First field is just with custom fields, as it shows in picture.
Second field is this pauses count in event.
If pauses was 0.0422004 sec in 9 events, then it would be like this 0-1 | 9
If pauses was 3,4376 sec in 5 events, then it would be like this 3-4 | 5

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...