Splunk查询问题:无法同时统计总事件与异常数以计算占比
问题根源
连续使用两个stats命令的逻辑错误:第一个stats count as dailyEventCount by date执行后,结果集里只剩下date和dailyEventCount字段,exception字段已被丢弃。第二个stats count as exceptionCount by date exception因找不到exception字段,无法按异常类型分组统计,最终得不到有效数据,返回空表。
修正后的查询
index=my_index source=my_source | fields logger exception message | fields - _raw | eval date=strftime(_time, "%F") | eval exception=case( isnull(exception), "null", like(exception,"%TaskDecorator%"), "ThreadPool Exhausted", like(exception,"%which is larger than%"), "Message too large", like(exception, "%has passed since batch creation"), "Expiring records", like(exception, "Disconnected from node%"), "Disconnected from node", true(), exception ) | stats count as exceptionCount by date exception | eventstats sum(exceptionCount) as dailyEventCount by date | eval exceptionPct=round(exceptionCount/dailyEventCount*100,2) | where exception="Message too large" | table date exceptionCount dailyEventCount exceptionPct
逻辑说明
- 先通过
stats count as exceptionCount by date exception统计每日每种异常的发生次数,保留date、exception、exceptionCount三个核心字段。 - 用
eventstats sum(exceptionCount) as dailyEventCount by date计算每日总事件数,eventstats会将统计结果追加到每一行,不会丢弃原有字段。 - 后续的百分比计算、异常过滤和表格展示即可正常执行。
内容的提问来源于stack exchange,提问作者cptully
相关产品推荐
相关产品推荐

