I have a search that find a match of events
this counts all events that match the string
index=data-kia-cer-app-n sourcetype=cer | regex "BLOCK,\d*,\d*,1"| stats count as "default"
I would like a search that results in a percent figure of this match as proportion of all events.
Thanks
Hi,
This adds a column "total" and "percentage" to the table:
index=data-kia-cer-app-n sourcetype=cer
| eventstats count as total
| regex "BLOCK,\d*,\d*,1"
| stats count as "default" by total
| eval percentage=(default*100)/total
You might want to remove some decimals and add a "%" to the percentage field..
Hi,
This adds a column "total" and "percentage" to the table:
index=data-kia-cer-app-n sourcetype=cer
| eventstats count as total
| regex "BLOCK,\d*,\d*,1"
| stats count as "default" by total
| eval percentage=(default*100)/total
You might want to remove some decimals and add a "%" to the percentage field..
Thanks. This worked!!