I do not understand how the field_from_search1 is designated in the (Conditions for search1) and, likewise, for the search2. Assuming the string "success" and "error" are the indicators in the lines pulled, I tried the following and it did not work: common_field !=NULL ("success" common_field as successes) OR ("error" common_field as errors) | stats count(errors) as errorCount count(successes) as successCount by common_field | eval ratio=(100*errorCount)/1+errorCount+successCount | timechart avg(ratio) by common_field The "1+" is to avoid division by zero. What is wrong with the above? I think I have the field-extraction in the first line wrong but, if so, I do not know the correct syntax to use there.
... View more