Splunk Search

One field and multiple custom values and get percentages

pudanelilita
Explorer

Hi,
I need hep to create table, which shows multiple custom values / field count / %
example, how it need to look:

alt text

Tags (1)
0 Karma

Adrian_ftx
Path Finder

Hi pudanelilita,

Can you provide a sample of your data please?
We can't give you the expected result if we don't have sample of your data.

Best regards,
Adrian

0 Karma

pudanelilita
Explorer

Event:
2019-08-28T14:05:27.078+0000: 89492.967: [GC pause (G1 Evacuation Pause) (young), **0.0422004** secs]
[Parallel Time: 29.3 ms, GC Workers: 13]
[GC Worker Start (ms): Min: 89492967.4, Avg: 89492967.5, Max: 89492967.6, Diff: 0.3]
[Ext Root Scanning (ms): Min: 7.0, Avg: 8.0, Max: 14.8, Diff: 7.8, Sum: 104.5]
[Update RS (ms): Min: 1.4, Avg: 7.4, Max: 8.5, Diff: 7.1, Sum: 96.6]
[Processed Buffers: Min: 3, Avg: 21.3, Max: 49, Diff: 46, Sum: 277]
[Scan RS (ms): Min: 0.1, Avg: 0.3, Max: 0.4, Diff: 0.3, Sum: 3.4]
[Code Root Scanning (ms): Min: 0.0, Avg: 0.0, Max: 0.0, Diff: 0.0, Sum: 0.1]
[Object Copy (ms): Min: 12.3, Avg: 13.1, Max: 13.4, Diff: 1.1, Sum: 170.3]
[Termination (ms): Min: 0.0, Avg: 0.0, Max: 0.0, Diff: 0.0, Sum: 0.0]
[Termination Attempts: Min: 1, Avg: 1.0, Max: 1, Diff: 0, Sum: 13]
[GC Worker Other (ms): Min: 0.0, Avg: 0.1, Max: 0.2, Diff: 0.2, Sum: 1.8]
[GC Worker Total (ms): Min: 28.8, Avg: 29.0, Max: 29.2, Diff: 0.4, Sum: 376.7]
[GC Worker End (ms): Min: 89492996.4, Avg: 89492996.5, Max: 89492996.6, Diff: 0.2]
[Code Root Fixup: 0.0 ms]
[Code Root Purge: 0.0 ms]
[Clear CT: 0.9 ms]
[Other: 12.0 ms]
[Choose CSet: 0.0 ms]
[Ref Proc: 8.7 ms]
[Ref Enq: 0.2 ms]
[Redirty Cards: 0.4 ms]
[Humongous Register: 0.2 ms]
[Humongous Reclaim: 0.1 ms]
[Free CSet: 1.8 ms]
[Eden: 7540.0M(7540.0M)->0.0B(7440.0M) Survivors: 64.0M->112.0M Heap: 13.4G(15.0G)->6260.5M(15.0G)]
[Times: user=0.39 sys=0.01, real=0.04 secs]

First field is just with custom fields, as it shows in picture.
Second field is this pauses count in event.
If pauses was 0.0422004 sec in 9 events, then it would be like this 0-1 | 9
If pauses was 3,4376 sec in 5 events, then it would be like this 3-4 | 5

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...