0
我試圖通過計算events(with error)
/total events
來計算錯誤的平均數量。Splunk appendcols不查詢所有事件
這裏是我的查詢
...| stats count(_raw) as Total
| appendcols [search .... error
| rex "(?i)^[^\\.]*\\.\\w+:\\s+(?P<FIELDNAME>.+)"
|stats count as errors by FIELDNAME ]
|eval average = errors/Total|sort -errors
結果:
FIELDNAME errors Total average
abc 10
def 2
ghi 2 30 0.0666
jkl 1
mno 1
預期結果
FIELDNAME errors Total average
abc 10 30 3.3
def 2 30 0.66
ghi 2 30 0.0666
jkl 1 30 0.33
mno 1 30 0.33
爲什麼不爲所有事件計算total
?