Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Charting results by a _time bucket, a calculated percentage of a count of events flagged in the bucket, in separate series on one chart

$
0
0
I have stats results from a search which form what amounts to a transaction per row on the order of several thousands of rows per hour. The transaction has relevant for this chart the following: _time, a flag "RED" or "GREEN", and a location code which is one of several codes. I want to bin _time by the hour and display a percentage as GREEN/(RED+GREEN) on a line graph with a line for each location in the series. This basically calculates the performance per location based on a percentage on the hour over time. I've tried several things and it's just not working, so maybe someone can shortcut me here. simplified example for a time bucket 12345: _time location_code flag 12345 A GREEN 12345 A GREEN 12345 A RED 12345 B RED 12345 C GREEN 12345 C GREEN Thanks!

Viewing all articles
Browse latest Browse all 47296

Trending Articles