Reference

Percentage_of

The Percentage_of function calculates the percentage value where the condition is met.

Updated 2026-08-17


Percentage_of

The Percentage_of function calculates the percentage value where the condition is met. The following illustrates the syntax of the percentage_of function:

Stream=FIREWALL | groupby dstip | select dstip, percentage_of(dstport==23) | having percentage_of_col1>0

Here,

  • Stream is Firewall
  • Groupby function allows to organize similar data into groups i.e. groupby destination IP Address.
  • Select function helps you to retrieve records from one or more tables, the records retrieved are known as a result set.
  • The percentage_of (condition) function returns the percentage value of a numeric column.

In this example, on execution it should retrieve all fields for each event where the stream is a firewall; it retrieves the percentage value in each group. The output is shown as below:

Related

Was this page helpful?

We use cookies to provide essential site functionality and, with your consent, to analyze site usage and enhance your experience. View our Privacy Policy