<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get Two Sum in the same query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81939#M20779</link>
    <description>&lt;P&gt;I'm not sure what you mean by status having multiple values (your examples only list one per event), but in general you're probably thinking of something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...  | stats count by status | eventstats sum(count) as total | eval ratio = count / total
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This counts events for every status individually, then adds the total to every line and computes the ratio between each status and the total.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2013 08:42:58 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2013-01-09T08:42:58Z</dc:date>
    <item>
      <title>How to get Two Sum in the same query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81938#M20778</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;My dataset is like below:&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;01/05/2013 23:58:00 -0800, search_name=foo, search_now=1357459200.000, info_min_time=1357459080.000, info_max_time=1357459200.000, info_search_time=1357459425.558, Count=1, apiName="footest", appName="bartest", clRT=70, status=401, svRT=68&lt;/P&gt;

&lt;P&gt;01/05/2013 23:58:00 -0800, search_name=foo, search_now=1357459200.000, info_min_time=1357459080.000, info_max_time=1357459200.000, info_search_time=1357459425.558, Count=10, apiName="footest1", appName="bartest1", clRT=50, status=200, svRT=52&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Here I would like to get a sum of field "Count" for all the Txns with "status" between 200-400(say Total_one ) and in the same query I also want to get total "Count" no matter what the status is (say, Total_two). And eventually I want to get (Total_one/Total_two).&lt;BR /&gt;
here "status" has multiple values between 200-500. Above are just for sample data.&lt;/P&gt;

&lt;P&gt;Can you please help?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:04:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81938#M20778</guid>
      <dc:creator>samsplunkd</dc:creator>
      <dc:date>2020-09-28T13:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Two Sum in the same query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81939#M20779</link>
      <description>&lt;P&gt;I'm not sure what you mean by status having multiple values (your examples only list one per event), but in general you're probably thinking of something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...  | stats count by status | eventstats sum(count) as total | eval ratio = count / total
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This counts events for every status individually, then adds the total to every line and computes the ratio between each status and the total.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 08:42:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81939#M20779</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-09T08:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Two Sum in the same query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81940#M20780</link>
      <description>&lt;P&gt;Thanks for your reply. Yes status has only one value per event but different values in different events..&lt;BR /&gt;
Above query would not calculate the sum of field "Count" Also I need to get only one value as a result which is ratio only for status between 200-400 so something like (sum of "Count" for status between 200-400)/Total sum(Count).&lt;BR /&gt;
I tried something like this but couldn't figure out a way to get only one value as explained above.&lt;/P&gt;

&lt;P&gt;| stats sum(Count) AS Total by responseCode| eventstats sum(Total) as TotalTxns| eval ratio=Total/TotalTxns&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 09:02:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81940#M20780</guid>
      <dc:creator>samsplunkd</dc:creator>
      <dc:date>2013-01-09T09:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Two Sum in the same query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81941#M20781</link>
      <description>&lt;P&gt;Ah, I guess I missed that you already have sort-of aggregated values in your event. How about something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | stats sum(Count) as s by status  | eventstats sum(s) as total | where status &amp;gt;= 200 AND status &amp;lt;= 400 | eventstats sum(s) as subtotal | head 1 | eval ratio = subtotal / total | fields + ratio
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This first calculates a total of all sums, then kicks out the rows for status&amp;lt;200 and status&amp;gt;400, then calculates a total of those remaining, and evals the ratio.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 09:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81941#M20781</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-09T09:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Two Sum in the same query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81942#M20782</link>
      <description>&lt;P&gt;Awesome. worked. &lt;BR /&gt;
Thanks for the quick help.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 09:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Two-Sum-in-the-same-query/m-p/81942#M20782</guid>
      <dc:creator>samsplunkd</dc:creator>
      <dc:date>2013-01-09T09:37:33Z</dc:date>
    </item>
  </channel>
</rss>

