Splunk Search

Calculate % of each field as ratio?

Joycetran
New Member

I have the table:
_time Ip_1 Ip_2 Ip_3
a 36 40 31
b 37 39 21

I want to take the percentage of each IP instead count, like:
a 0.33 0.37 0.28
The table above From the query:
base search | | stats dc(sid) AS distinct_search_count by provenance, mode, app, type, user, host, _time

| stats sum(distinct_search_count) as total_distinct_search_count by provenance, mode, app, type, user, host, _time

How can I add the percentage in the query?
| timechart minspan=10s partial=false Max(total_distinct_search_count) as search_count by host

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Give this a try

base search | | stats dc(sid) AS distinct_search_count by provenance, mode, app, type, user, host, _time 
| stats sum(distinct_search_count) as total_distinct_search_count by provenance, mode, app, type, user, host, _time
| timechart minspan=10s partial=false Max(total_distinct_search_count) as search_count by host
| addtotals 
| foreach * [| eval "<<FIELD>>"=if("<<FIELD>>"!="Total", round('<<FIELD>>'/Total,2), '<<FIELD>>') ]

View solution in original post

0 Karma

somesoni2
Revered Legend

Give this a try

base search | | stats dc(sid) AS distinct_search_count by provenance, mode, app, type, user, host, _time 
| stats sum(distinct_search_count) as total_distinct_search_count by provenance, mode, app, type, user, host, _time
| timechart minspan=10s partial=false Max(total_distinct_search_count) as search_count by host
| addtotals 
| foreach * [| eval "<<FIELD>>"=if("<<FIELD>>"!="Total", round('<<FIELD>>'/Total,2), '<<FIELD>>') ]
0 Karma

Joycetran
New Member

I never use Foreach before. thank you for giving this query. It works

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...