Splunk Search

Piechart split for selected hostname?

super_edition
Path Finder

Hello Everyone,

I am trying to create piechart for cache operation split(in percentage) for hit/miss/pass using the below query for the selected hostname:

 

index="my_index" openshift_container_name="container" 
| eval description=case(handling == "hit","HIT", handling == "miss","MISS", handling == "pass","PASS")
| search hostname="int-ie-yyp.grp"
| addtotals
| eval cache_hit=round(100*HIT/Total,1)
| eval cache_miss=round(100*MISS/Total,1)
| eval cache_pass=round(100*PASS/Total,1)

 


When I try with:

 

| stats values(cache_hit) as cacheHit values(cache_miss) as cacheMiss values(cache_pass) as cachePass by description

 

 no data is generated.

super_edition_0-1688638043231.png

However when I try for count it works:

 

| stats count by description

 

super_edition_1-1688638447379.png

Can someone please help.

 



Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| stats count by description
| eventstats sum(count) as Total
| eval percent=100*count/Total
| fields description percent

View solution in original post

0 Karma

super_edition
Path Finder

Its working as expected. Thank you @ITWhisperer 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats count by description
| eventstats sum(count) as Total
| eval percent=100*count/Total
| fields description percent
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...