The simplest way is to use the top command
index=proxy sourcetype=bar
| top 0 blockedAction
but you can do this other ways, such as
index=proxy sourcetype=bar
| stats count by blockedAction
| eventstats sum(count) as grandTotal
| eval percentBlocked = round((count/grandTotal)*100,1)
| fields - grandTotal
Hope this helps
It would be helpful to know what results you get from that query, but I expect you get no results. If you do get results then they're likely to be inaccurate because the blockedAction field is a label rather than a count.
Try this variation on your query.
index=proxy sourcetype=bar
| stats count as grandTotal, sum(eval(blockedAction="blocked")) as blockedCount
| eval percentBlocked = round((blockedCount/grandTotal)*100,1)
The simplest way is to use the top command
index=proxy sourcetype=bar
| top 0 blockedAction
but you can do this other ways, such as
index=proxy sourcetype=bar
| stats count by blockedAction
| eventstats sum(count) as grandTotal
| eval percentBlocked = round((count/grandTotal)*100,1)
| fields - grandTotal
Hope this helps