Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Get percentage of values for a field based on total number from different search

$
0
0
Hi, I have been pulling my hair to get this to work, but couldn't, and any help would be very much appreciated. I have a set of events created for when `tickets` are created. One of field is `created` time like this: `2019-08-26T18:20:08.930Z` I have another set of events created for when some type of query is made for `ticket`, and it includes time when the ticket was originally created. I would like to create a table of percentage of type of queries made from total number of orders created on the date. For example, ticket events are like the following: `{"event":"ticket_created","ticket_id": "id_1", "created": "2019-08-26T18:20:08.930Z"}, {"event":"ticket_created","ticket_id": "id_2", "created": "2019-08-26T18:20:08.930Z"}, {"event":"ticket_created","ticket_id": "id_3", "created": "2019-08-26T18:20:08.930Z"},` And query events would be like this: `{"event":"query","query_type":"type1","ticket_id": "id_1", "ticket_created": "2019-08-26T18:20:08.930Z"}, {"event":"query","query_type":"type2","ticket_id": "id_2", "ticket_created": "2019-08-26T18:20:08.930Z"},` And table I am trying to create (from which visualization can be created): `Date type1 type2` `2019-08-26 33% (1 out of 3 tickets) 33% (1 out of 3 tickets)` `2019-08-27 N% M%` `2019-08-28 I% J%` So, far I was only able to generate just total numbers (query types by converted date appended with total ticket count by converted date). I can't seem to figure out how to dynamically divide sum of types divided by total number of tickets grouped by converted date. Any help would be much, much appreciated.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>