0
我试图通过计算events(with error)
/total events
来计算错误的平均数量。Splunk appendcols不查询所有事件
这里是我的查询
...| stats count(_raw) as Total
| appendcols [search .... error
| rex "(?i)^[^\\.]*\\.\\w+:\\s+(?P<FIELDNAME>.+)"
|stats count as errors by FIELDNAME ]
|eval average = errors/Total|sort -errors
结果:
FIELDNAME errors Total average
abc 10
def 2
ghi 2 30 0.0666
jkl 1
mno 1
预期结果
FIELDNAME errors Total average
abc 10 30 3.3
def 2 30 0.66
ghi 2 30 0.0666
jkl 1 30 0.33
mno 1 30 0.33
为什么不为所有事件计算total
?