I am looking to figure out the percentage of times certain value combinations appear in the data. The field I am looking to construct in the sample below is "combo."
In the sample the A value appears in 30% of all events, Y appears in 30% of all events, and the combination of AY appears in 10% of all events. Pieces of the following code have worked by themselves but not together.
... | stats count by Field1 Field2 as combo | eventstats sum(count) as total | eval perc=(combo/total)
| eval _raw="Field1 Field2 combo
A Y 10
A Z 20
B Y 20
B Z 40
C Z 10"
| multikv forceheader=1
| table Field1 Field2 combo
| rename COMMENT as "this is logic"
| eval Field3=Field1.Field2
| untable combo name Fields
| eventstats sum(eval(if(name="Field3",combo,NULL))) as total
| stats sum(combo) as count max(total) as total by Fields
| eval perc=count/total * 100