<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New to splunk, looking for total calculator by week in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557839#M92315</link>
    <description>&lt;P&gt;So far I think I have the syntax built out like this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index=tool OR index=tool2 OR index=tool3&lt;BR /&gt;| eval parta=(index=tool information, information | stats count)&lt;BR /&gt;| eval partb=(index=tool2 information, information | stats count)&lt;BR /&gt;| eval partc=(index=tool3 information, | stats count)&lt;BR /&gt;| table parta partb partc &lt;/PRE&gt;&lt;P&gt;Thinking this will get me totals for the separate tools, but I'm looking to get just 1 total, per week if possible. I was thinking addtotals would help, but not sure.&amp;nbsp; Any and all help would be very appreciated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2021 15:13:55 GMT</pubDate>
    <dc:creator>teegarden7070</dc:creator>
    <dc:date>2021-06-30T15:13:55Z</dc:date>
    <item>
      <title>New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557839#M92315</link>
      <description>&lt;P&gt;So far I think I have the syntax built out like this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index=tool OR index=tool2 OR index=tool3&lt;BR /&gt;| eval parta=(index=tool information, information | stats count)&lt;BR /&gt;| eval partb=(index=tool2 information, information | stats count)&lt;BR /&gt;| eval partc=(index=tool3 information, | stats count)&lt;BR /&gt;| table parta partb partc &lt;/PRE&gt;&lt;P&gt;Thinking this will get me totals for the separate tools, but I'm looking to get just 1 total, per week if possible. I was thinking addtotals would help, but not sure.&amp;nbsp; Any and all help would be very appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 15:13:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557839#M92315</guid>
      <dc:creator>teegarden7070</dc:creator>
      <dc:date>2021-06-30T15:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557845#M92318</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=tool OR index=tool2 OR index=tool3
| bin _time span=1w
| stats count by index _time&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 30 Jun 2021 15:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557845#M92318</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-30T15:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557846#M92319</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235693"&gt;@teegarden7070&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you looking for something this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just execute for last 7 days OR week.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=tool OR index=tool2 OR index=tool3
| stats count by index | addcoltotals&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=tool OR index=tool2 OR index=tool3
| stats count  &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 07:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557846#M92319</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-01T07:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557850#M92321</link>
      <description>&lt;P&gt;Awesome thanks for the help!&amp;nbsp; I guess the timeframe isn't such a huge deal because I can adjust the parameters of the search, the problem I'm having is the search itself.&amp;nbsp; Each one of the tools has a separate event that I want to use to find the total count of event.&amp;nbsp; All the other fields do not necessarily help with a total count.&amp;nbsp; So all in all I want to index a tool, then get a total count by event in that tool, then be able to display it. If I'm not making sense feel free to critique my thinking.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 16:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557850#M92321</guid>
      <dc:creator>teegarden7070</dc:creator>
      <dc:date>2021-06-30T16:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557852#M92323</link>
      <description>&lt;P&gt;For example, if I use the index= all tools, and then add a field where it doesnt count all the events, only a few&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 16:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557852#M92323</guid>
      <dc:creator>teegarden7070</dc:creator>
      <dc:date>2021-06-30T16:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557856#M92324</link>
      <description>&lt;P&gt;Can you share some sample events from the different indexes showing the different events you want to count? Best to share these in code blocks &amp;lt;/&amp;gt; so they are easier to use for testing solutions.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 16:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557856#M92324</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-30T16:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557890#M92325</link>
      <description>&lt;P&gt;Sure, I can try, but I would like to stay as generic as possible:&lt;/P&gt;&lt;P&gt;index=tool1 OR index=tool2 OR index=too3&lt;/P&gt;&lt;P&gt;So I would like to index the 3 of these tools, but search for specific fields with each tool.&amp;nbsp; Lets say,&amp;nbsp;&lt;/P&gt;&lt;P&gt;tool1 field I want is called field 1, tool 2 is called field 2, and tool 3 is called field 3.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hate to be so vague, and I really do appreciate the help.&amp;nbsp; I can do a:&amp;nbsp;&lt;/P&gt;&lt;P&gt;|stats count by field 1,&amp;nbsp; but not sure how to get the counts and display all 3 fields.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 18:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/557890#M92325</guid>
      <dc:creator>teegarden7070</dc:creator>
      <dc:date>2021-06-30T18:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/558002#M92333</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235693"&gt;@teegarden7070&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With this use case I would like to suggest to go with below approach where we fetch only those event which have specific fields as you mentioned from below search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=tool1 field1=*) OR (index=tool2 field2=*) OR (index=too3 field3=*)&lt;/LI-CODE&gt;&lt;P&gt;After this just do stats by index.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats count by index &lt;/LI-CODE&gt;&lt;P&gt;at this level the index will have the count which has specific field.&lt;/P&gt;&lt;P&gt;You can add&amp;nbsp;| addcoltotals command or remove by index from above search.&lt;/P&gt;&lt;P&gt;like,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=tool1 field1=*) OR (index=tool2 field2=*) OR (index=too3 field3=*)
| stats count by index 
| addcoltotals&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=tool1 field1=*) OR (index=tool2 field2=*) OR (index=too3 field3=*)
| stats count  &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To get weekly count you can try this also.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=tool1 field1=*) OR (index=tool2 field2=*) OR (index=too3 field3=*)
| bin _time span=w
| stats count by index _time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help you.&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 07:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/558002#M92333</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-01T07:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: New to splunk, looking for total calculator by week</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/558025#M92337</link>
      <description>&lt;P&gt;This is great! Thank you so much for all of your help!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 12:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/New-to-splunk-looking-for-total-calculator-by-week/m-p/558025#M92337</guid>
      <dc:creator>teegarden7070</dc:creator>
      <dc:date>2021-07-01T12:41:10Z</dc:date>
    </item>
  </channel>
</rss>

