# Calculating purcentage in a metric

**URL:** <https://discuss.elastic.co/t/calculating-purcentage-in-a-metric/211652>\
**Category:** Kibana\
**Tags:** canvas\
**Created:** [December 12, 2019, 1:13pm UTC](https://discuss.elastic.co/t/calculating-purcentage-in-a-metric/211652 "2019-12-12T13:13:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AchrafNGZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/achrafngz/32/59279_2.png) [@AchrafNGZ](https://discuss.elastic.co/u/AchrafNGZ)\
**Post date:** [December 12, 2019, 1:13pm UTC](https://discuss.elastic.co/t/calculating-purcentage-in-a-metric/211652/1 "2019-12-12T13:13:02Z")

</div>

Hello,  
Sorry if its not the right section, thats cause im new ☹

Im facing an issue with a codec expression that should allow me to calculate the purcentage of Symantec Endpoint Protection (SEP) client that have the Antivirus engine ON.

Bellow is my script

essql ""  
query="SELECT COUNT(host.id) AS asset, COUNT(antivirus.avengine\_onoff) AS AVon FROM "soc-asset-sep-_" WHERE (antivirus.lastupdate \> NOW()- INTERVAL 20 DAYS AND antivirus.avengine\_onoff like 'Enabled')"  
| math  
{string "asset/" {filters group="host.id" ungrouped=true | essql "" query="SELECT COUNT(host.id) AS asset, COUNT(antivirus.avengine\_onoff) AS AVon FROM "soc-asset-sep-_" WHERE (antivirus.lastupdate \> NOW()- INTERVAL 20 DAYS) and antivirus.avengine\_onoff like 'Enabled'" | math "AVon"}}  
| formatnumber "0%"  
| metric  
metricFont={font size=48 family="'Open Sans', Helvetica, Arial, sans-serif" color="#000000" align="center" lHeight=48}  
labelFont={font size=14 family="'Open Sans', Helvetica, Arial, sans-serif" color="#000000" align="center"}  
| render

This only show (in the preview) a list of the IDs with the status of the AVengine Enabled, how can i tranlate it to a % ?

Thanks you in advance for you help.

Kind regards  
N.Achraf

---

<div class="post-metadata">

**Author:** ![corey.robertson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/corey.robertson/32/54611_2.png) [@corey.robertson](https://discuss.elastic.co/u/corey.robertson)\
**Post date:** [December 12, 2019, 4:45pm UTC](https://discuss.elastic.co/t/calculating-purcentage-in-a-metric/211652/2 "2019-12-12T16:45:55Z")

</div>

Hi @AchrafNGZ

I think you have an issue in your expression with some unescaped strings. You have quotes around the index name `"soc-asset-sep-"` but that is in the larger `query="" ` so those unescaped quotes are breaking the expression. You can escape them with a backslash like `FROM "soc-asset-sep-"

Here is a similar expression using one of our sample data sets to display a percent metric of orders that contain exactly 2 unique products.

```auto
filters
| essql
query="SELECT count(total_quantity) as cnt FROM \"kibana_sample_data_ecommerce\"
where total_unique_products = 2"
| math {string "cnt/" {filters | essql query="SELECT count(*) as cnt FROM \"kibana_sample_data_ecommerce\"" | math "cnt" }}
| formatnumber "0%"
| metric label="Percent of orders with 2 unique products"
| render

```

Hope that helps

---

<div class="post-metadata">

**Author:** ![AchrafNGZ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/achrafngz/32/59279_2.png) [@AchrafNGZ](https://discuss.elastic.co/u/AchrafNGZ)\
**Post date:** [December 13, 2019, 7:30am UTC](https://discuss.elastic.co/t/calculating-purcentage-in-a-metric/211652/3 "2019-12-13T07:30:14Z")

</div>

Hi @corey.robertson & thank you for your replay,

When tuning your expression, i have the value of the assets (when i click preview) but it give 100%, its lke its not doing any math ☹

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 7:30am UTC](https://discuss.elastic.co/t/calculating-purcentage-in-a-metric/211652/4 "2020-01-10T07:30:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
