Splunk Search

timechart sum Communicator

index="acoe_np_spa_metrics"
| search Project="*" AND Volume="*"
| timechart span=1mon count(eval(D_Status="F")) as success_count
count(eval(D_Status="S")) as failure_count count as Total
| eval STP=(success_count/Total)*100
| fields - Total

Good day, I have the above SPL query it gives me the count of "F"s and "S"s but I need the sum of Volumes where D_Status = F and sum of Volume where D_Status = S

Labels (3)

• fields

1 Solution  SplunkTrust

index="acoe_np_spa_metrics"
| search Project="*" AND Volume="*"
| timechart span=1mon sum(eval(if(D_Status="F",Volume,0))) as success_count
count(eval(if(D_Status="S",Volume,0))) as failure_count count as Total
| eval STP=(success_count/Total)*100
| fields - Total

Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.  SplunkTrust

index="acoe_np_spa_metrics"
| search Project="*" AND Volume="*"
| timechart span=1mon sum(eval(if(D_Status="F",Volume,0))) as success_count
count(eval(if(D_Status="S",Volume,0))) as failure_count count as Total
| eval STP=(success_count/Total)*100
| fields - Total

Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated. Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE! Catch Up Now >>

Get Updates on the Splunk Community!