You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk查询问题:无法同时统计总事件与异常数以计算占比

问题根源

连续使用两个stats命令的逻辑错误:第一个stats count as dailyEventCount by date执行后,结果集里只剩下date和dailyEventCount字段,exception字段已被丢弃。第二个stats count as exceptionCount by date exception因找不到exception字段,无法按异常类型分组统计,最终得不到有效数据,返回空表。

修正后的查询

index=my_index source=my_source
  | fields logger exception message 
  | fields - _raw
  | eval date=strftime(_time, "%F")
  | eval exception=case( isnull(exception),
                            "null",
                         like(exception,"%TaskDecorator%"),
                            "ThreadPool Exhausted",
                         like(exception,"%which is larger than%"),
                             "Message too large",
                         like(exception, "%has passed since batch creation"),
                             "Expiring records",
                         like(exception, "Disconnected from node%"),
                             "Disconnected from node",
                         true(),
                             exception )
   | stats count as exceptionCount by date exception
   | eventstats sum(exceptionCount) as dailyEventCount by date
   | eval exceptionPct=round(exceptionCount/dailyEventCount*100,2)
   | where exception="Message too large"
   | table date exceptionCount dailyEventCount exceptionPct

逻辑说明

  1. 先通过stats count as exceptionCount by date exception统计每日每种异常的发生次数,保留date、exception、exceptionCount三个核心字段。
  2. 用eventstats sum(exceptionCount) as dailyEventCount by date计算每日总事件数,eventstats会将统计结果追加到每一行,不会丢弃原有字段。
  3. 后续的百分比计算、异常过滤和表格展示即可正常执行。

内容的提问来源于stack exchange,提问作者cptully

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 04:05:30