You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Splunk查询计算HTTP 401失败请求的占比

解决方案

修改后的完整Splunk查询语句

<base query>  | rex field=msg "HTTP/1.1\\\" (?<http_status>\d{3})" 
| where http_status=200 OR http_status=401 
| eval event_date=strftime(_time, "%x") 
| chart count over event_date by http_status
| fillnull value=0 200 401
| eval "401 percentage" = round(('401' / ('200' + '401')) * 100, 2) 
| eval "401 percentage" = tostring('401 percentage') + "%"

逻辑说明

  • fillnull 语句用于避免某一天不存在200或401状态码的请求时,字段缺失导致计算报错,默认给缺失字段赋值为0
  • Splunk中数字开头的字段名需要用单引号包裹,避免被识别为普通数值,因此引用200、401字段时都加了单引号
  • round 函数用来将计算结果保留两位小数,匹配预期的输出精度
  • 最后将计算得到的数值转为字符串拼接百分号,即可得到符合要求的百分比格式展示

内容的提问来源于stack exchange,提问作者user5245796

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 14:15:06