Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to use eval to find percentage for field values?

$
0
0
I have values for a field named action, block, passed, and alerted. How would I go about creating a search to looks for the percentage of blocked to passed/alerted events? I have the basic search of index=foo | stats count by src, action | stats list(action) as Action, list(count) as count, sum(count) as Total by src and was thinking eval could be used in some way Thx

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>