Hi,
I have a query like:
index=federated:ccs_rmail sourcetype="rmail:KIC:reports"
| dedup _time
| timechart span=1mon sum(cisco_*) as cisco_*
| addtotals
| eval rep_perc = round(cisco_stoppedbyreputation/Total*100,2),
spam_perc =round(cisco_spam/Total*100,2),
virus_perc=round(cisco_virus/Total*100,6)
| table cisco_stoppedbyreputation,rep_perc,cisco_spam,spam_perc,cisco_virus,virus_perc
| rename cisco_spam as spam, cisco_virus as virus,cisco_stoppedbyreputation as reputation
| transpose
The result look like:
column
row 1
reputation
740284221
rep_perc
82.46
spam
9695175
spam_perc
1.08
virus
700
virus_perc
0.000078
Is it possible to have something like this?
Name
#
%
reputation
740284221
82.46
spam
9695175
1.08
virus
700
0.000078
Thanks, Emile
... View more