Hello Splunkers, I have a field called state_sinfo which have values like (up,up*,up$,up^,continue,continue$,continued,continied$,down,down%,down#,drop,drop*,drop$) I want to categorize certain v...
See more...
Hello Splunkers, I have a field called state_sinfo which have values like (up,up*,up$,up^,continue,continue$,continued,continied$,down,down%,down#,drop,drop*,drop$) I want to categorize certain values of state_sinfo as like below available (up,up*,up$,up^,continue,continue$,continued,continied$) not_available(down,down%,down#) down(drop,drop*,drop$) Then I want to calculate the sum of all categories by time Lastly I want to calculate the percentage | eval "% available" = round( available / ( available + drop ) * 100 , 2) | eval "% drained" = round( drop / (available + drop ) * 100 , 2) Sample event slu_ne_state{instance="192.1x.x.x.",job="exporters",node="xyz",partition="gryr",state_sinfo="down",state_sinfo_simple="maint"} 1.000000 1676402381347 Thanks In advance