<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to calculate total when aggregating using stats max(field)? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660427#M228065</link>
    <description>&lt;P&gt;You *think* your search will produce that output?&amp;nbsp; Why not run the search and remove the doubt?&lt;/P&gt;&lt;P&gt;To calculate a total, use the &lt;FONT face="courier new,courier"&gt;sum&lt;/FONT&gt; function.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| index=scoreindex   
| stats values(Name) as Name, values(Subject) as Subject,  sum(TotalScore) as TotalScore, max(Score1) as Score1, max(Score2) as Score2, max(Score3) as Score3, max(TotalScore) as "Max TotalScore" by Class
| table Class, Name, Subject, TotalScore, Score1, Score2, Score3, "Max TotalScore"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 17:11:50 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-10-11T17:11:50Z</dc:date>
    <item>
      <title>How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660403#M228063</link>
      <description>&lt;P&gt;How to calculate total when aggregating using stats max(field)?&lt;BR /&gt;Thank you for your help.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Max Total Score&lt;/STRONG&gt; is the total score of maximum score for each Score field when aggregating all rows using stats: max(Score1), max(Score2), max(Score3).&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt; is the total of each Score field for each row (without aggregation)&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;This is the output I need&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="557"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="72"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="101"&gt;&lt;STRONG&gt;Max TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64"&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;grouped&lt;/TD&gt;&lt;TD width="64"&gt;grouped&lt;/TD&gt;&lt;TD width="72"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="101"&gt;260&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;My Splunk Search&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| index=scoreindex   
| stats values(Name) as Name, values(Subject) as Subject,  max(TotalScore) as TotalScore, max(Score1) as Score1, max(Score2) as Score2, max(Score3) as Score3 by Class
| table Class Name, Subject, Total Score, Score1, Score2, Score3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I think my search below is going to display the following.&lt;/P&gt;&lt;TABLE width="462"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="78"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name1 Name2 Name3&lt;/TD&gt;&lt;TD width="64"&gt;Math English&lt;/TD&gt;&lt;TD width="78"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;This is the whole data in table format from scoreindex&lt;/P&gt;&lt;TABLE width="495"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="90"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="85"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name1&lt;/TD&gt;&lt;TD width="90"&gt;Math&lt;/TD&gt;&lt;TD width="85"&gt;170&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;40&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name1&lt;/TD&gt;&lt;TD width="90"&gt;English&lt;/TD&gt;&lt;TD width="85"&gt;195&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;50&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name2&lt;/TD&gt;&lt;TD width="90"&gt;Math&lt;/TD&gt;&lt;TD width="85"&gt;175&lt;/TD&gt;&lt;TD width="64"&gt;50&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;65&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name2&lt;/TD&gt;&lt;TD width="90"&gt;English&lt;/TD&gt;&lt;TD width="85"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="64"&gt;90&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name3&lt;/TD&gt;&lt;TD width="90"&gt;Math&lt;/TD&gt;&lt;TD width="85"&gt;170&lt;/TD&gt;&lt;TD width="64"&gt;40&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name3&lt;/TD&gt;&lt;TD width="90"&gt;English&lt;/TD&gt;&lt;TD width="85"&gt;230&lt;/TD&gt;&lt;TD width="64"&gt;55&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 11 Oct 2023 17:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660403#M228063</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-11T17:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660426#M228064</link>
      <description>&lt;P&gt;How is this different than what you asked here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660404" target="_blank"&gt;Solved: Re: How to display other fields on the same row wh... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's nearly the same question, and that linked post seems to have the answer to this post in it.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 17:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660426#M228064</guid>
      <dc:creator>_JP</dc:creator>
      <dc:date>2023-10-11T17:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660427#M228065</link>
      <description>&lt;P&gt;You *think* your search will produce that output?&amp;nbsp; Why not run the search and remove the doubt?&lt;/P&gt;&lt;P&gt;To calculate a total, use the &lt;FONT face="courier new,courier"&gt;sum&lt;/FONT&gt; function.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| index=scoreindex   
| stats values(Name) as Name, values(Subject) as Subject,  sum(TotalScore) as TotalScore, max(Score1) as Score1, max(Score2) as Score2, max(Score3) as Score3, max(TotalScore) as "Max TotalScore" by Class
| table Class, Name, Subject, TotalScore, Score1, Score2, Score3, "Max TotalScore"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 17:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660427#M228065</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-11T17:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660430#M228066</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Sorry I made a mistake on my original post. I just updated my question&lt;BR /&gt;I am looking for Max Total Score, a total score &lt;STRONG&gt;&lt;U&gt;after the aggregation&lt;BR /&gt;&lt;/U&gt;&lt;/STRONG&gt;Please suggest. Thank you&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Max Total Score&lt;/STRONG&gt;&amp;nbsp;= Max(Score1) + Max(Score2) + Max(Score3) = 85+95+80 = &lt;STRONG&gt;260&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;This is the output I need&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="557"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="72"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="101"&gt;&lt;STRONG&gt;Max TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64"&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;grouped&lt;/TD&gt;&lt;TD width="64"&gt;grouped&lt;/TD&gt;&lt;TD width="72"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="101"&gt;260&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 11 Oct 2023 17:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660430#M228066</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-11T17:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660431#M228067</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Sorry I made a mistake on my original post. I just updated my question&lt;BR /&gt;I am looking for Max Total Score, a total score &lt;STRONG&gt;&lt;U&gt;after the aggregation&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;(&lt;STRONG&gt;260&lt;/STRONG&gt;), before the aggregation Max(TotalScore) is 240 only for 1 row.&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;Please suggest. Thank you&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Max Total Score&lt;/STRONG&gt;&amp;nbsp;= Max(Score1) + Max(Score2) + Max(Score3) = 85+95+80 = &lt;STRONG&gt;260&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;This is the output I need&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="557"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="72"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="101"&gt;&lt;STRONG&gt;Max TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64"&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;grouped&lt;/TD&gt;&lt;TD width="64"&gt;grouped&lt;/TD&gt;&lt;TD width="72"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="101"&gt;260&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 11 Oct 2023 17:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660431#M228067</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-11T17:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660439#M228068</link>
      <description>&lt;P&gt;Something like that can be done using &lt;FONT face="courier new,courier"&gt;eval&lt;/FONT&gt;.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| index=scoreindex   
| stats values(Name) as Name, values(Subject) as Subject,  sum(TotalScore) as TotalScore, max(Score1) as Score1, max(Score2) as Score2, max(Score3) as Score3 by Class
| eval "Max TotalScore"=Score1 + Score2 + Score3
| table Class, Name, Subject, TotalScore, Score1, Score2, Score3, "Max TotalScore"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 18:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660439#M228068</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-11T18:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660443#M228069</link>
      <description>&lt;P&gt;I tested your suggestion and it worked even on real data with multiple "Classes" (Class A, B, C).&lt;BR /&gt;I thought eval would not work after passing "stats" pipe, so I tried to sum (Score1+Score2+Score3) within the stats, but it would not let me.&amp;nbsp; &amp;nbsp;I accepted this as a solution.&lt;BR /&gt;Could you give an explanation why it worked after passing "stats" function?&lt;BR /&gt;Thank you so much&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 19:09:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660443#M228069</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-11T19:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate total when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660446#M228070</link>
      <description>&lt;P&gt;I'm curious about why you thought &lt;FONT face="courier new,courier"&gt;eval&lt;/FONT&gt; would not work after &lt;FONT face="courier new,courier"&gt;stats&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;There's nothing particularly magical about &lt;FONT face="courier new,courier"&gt;stats&lt;/FONT&gt;.&amp;nbsp; It's a transforming command so only the fields used in the command are available to later commands.&amp;nbsp; They are still fields, however, and can be processed as such.&amp;nbsp; Note that some &lt;FONT face="courier new,courier"&gt;stats&lt;/FONT&gt; functions produce multi-value fields, which don't work well in all commands so they may require additional processing.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 19:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660446#M228070</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-11T19:18:12Z</dc:date>
    </item>
  </channel>
</rss>

