<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please Help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579696#M201991</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241841"&gt;@sumitp10797&lt;/a&gt;&amp;nbsp;Also if you received you answer please mark it as a solution so that I can be used by others for a reference.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Dec 2021 13:32:31 GMT</pubDate>
    <dc:creator>ashvinpandey</dc:creator>
    <dc:date>2021-12-31T13:32:31Z</dc:date>
    <item>
      <title>Please Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579642#M201975</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;Provide details about client purchase details&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1. Total purchase split by product ID&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2. Total Products&amp;nbsp;split by product ID&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;with raw data&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 06:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579642#M201975</guid>
      <dc:creator>sumitp10797</dc:creator>
      <dc:date>2021-12-31T06:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Please Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579643#M201976</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241841"&gt;@sumitp10797&lt;/a&gt;&amp;nbsp;Try using below queries:&lt;/P&gt;&lt;P&gt;1. Total purchase split by product ID&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=&amp;lt;&amp;lt;your_index&amp;gt; sourcetype=&amp;lt;&amp;lt;your_sourcetype&amp;gt;&amp;gt;
| stats sum(purchase_field) as purchase by product_id&lt;/LI-CODE&gt;&lt;P&gt;2. Total Products split by product ID&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=&amp;lt;&amp;lt;your_index&amp;gt; sourcetype=&amp;lt;&amp;lt;your_sourcetype&amp;gt;&amp;gt;
| stats sum(products_field) as products by product_id&lt;/LI-CODE&gt;&lt;P&gt;3. Both Combined Query:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=&amp;lt;&amp;lt;your_index&amp;gt; sourcetype=&amp;lt;&amp;lt;your_sourcetype&amp;gt;&amp;gt;
| stats sum(purchase_field) as purchase sum(products_field) as products by product_id&lt;/LI-CODE&gt;&lt;P&gt;Also, if this reply helped you in solving your problem an up-vote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 07:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579643#M201976</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-12-31T07:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Please Help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579696#M201991</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241841"&gt;@sumitp10797&lt;/a&gt;&amp;nbsp;Also if you received you answer please mark it as a solution so that I can be used by others for a reference.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 13:32:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Please-Help/m-p/579696#M201991</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-12-31T13:32:31Z</dc:date>
    </item>
  </channel>
</rss>

