Though this question seems similar to the other discussions, I'm having a hard time relating to them.
A network service has sites across the country in different cities. For example if there are 2 sites ( lets say seattle and woburn) I want to compare the total number of unique users from these two cities with the rest of the cities. So far, I'm only able to get the sum of the number of users from (woburn and seattle). Here's my search:
index=[] sourcetype=[] shn=$[]$ tier=[] | eval overseas_site=case(site=="us-ma-woburn" , "Overseas", site=="us-wa-seattle", "Overseas") | stats dc(chi) AS "OverseasUsers" by overseas_site
Currently this is only populating the total # of unique users from woburn and seattle. My goal is to maybe create another bucket that will store the total # of users from all the other sites. Then get the ratio of (users from seatle/woburn) to (rest of the cities). Basically trying to get the traffic ratio. Hope that makes sense and any help is appreciated! Thanks
... View more