Splunk Search

How to compare 2 Search's percentage results?

EBVanguard
Engager

Hey Team, 
I am trying to generate a search which returns a complete set of results from today and then compares it with a search whereby the results only came in between 4-5pm. 
I then want to work out the precentage of results which came in between 4-5pm.

So far I have:

EBVanguard_0-1663332163135.png

 

With the **** being where I think I need to timeframe search?

Thanks!

Labels (3)
0 Karma
1 Solution

maciep
Champion

So maybe just this then?

| stats count(eval(date_hour="16")) as ycount, totalcount

 

View solution in original post

0 Karma

maciep
Champion

So maybe just this then?

| stats count(eval(date_hour="16")) as ycount, totalcount

 

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...