I have logs like:
"The request failed"
"The request succeeded"
"The request failed"
"The request failed"
"The request succeeded"
I want to calculate failure % every day on the basis of the string ("failed" or "succeeded")
please help me correct this search (marked in ***):
...base search... | timechart span=1d ***eval((count("failed"))/((count("failed"))+(count ("succeeded"))))*** as failureRate
... View more
0
down vote
favorite
I want to draw a splunk chart and I have following strings in my logs:
"Request id: 552"
"Request id: 223"
"Request id: 365"
"Request id: 552"
"Request id: 552"
"Request id: 223"
I want to create a chart with x axis values as the request ids (552,223,365) and y axis values as number of occurrences of these request ids. What splunk search query would work?
... View more