Dear Splunk community:
So i have the following SPL that has been running fine for the last week or so however,
all of a sudden i am getting the last unwanted column (Value) which i don't expect to get.
Can you please explain, what i need to modify so that i don't get the last Value column?
<my serch> | chart count by path_template, http_status_code | addtotals fieldname=total
| foreach 2* 3* 4* 5* [ eval "percent_<<FIELD>>"=round(100*'<<FIELD>>'/total,2),
"<<FIELD>>"=if('<<FIELD>>'=0 , '<<FIELD>>', '<<FIELD>>'." (".'percent_<<FIELD>>'."%)")] | fields - percent_* total
Here is what is see:
Really appreciate your help on this!
Thanks!
It's not clear where the field is coming from, but it's easy to remove with fields - VALUE
It's not clear where the field is coming from, but it's easy to remove with fields - VALUE