<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to calculate sum of a field based on other distinct field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667206#M228888</link>
    <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Thank you so much for your help&lt;BR /&gt;&lt;STRONG&gt;Is it possible to do it in one stats, instead of two, so I can keep my previous original calculation?&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;I currently have stats ip with the following result&lt;/P&gt;&lt;TABLE width="529px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="59.9844px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="74.9375px"&gt;&lt;STRONG&gt;dc(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="151.141px"&gt;&lt;STRONG&gt;dc(vuln) score &amp;gt; 0&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="93.5px"&gt;&lt;STRONG&gt;count(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="148.438px"&gt;&lt;STRONG&gt;sum(score)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="59.9844px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="74.9375px"&gt;3&lt;/TD&gt;&lt;TD width="151.141px"&gt;2&lt;/TD&gt;&lt;TD width="93.5px"&gt;7&lt;/TD&gt;&lt;TD width="148.438px"&gt;23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="59.9844px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="74.9375px"&gt;3&lt;/TD&gt;&lt;TD width="151.141px"&gt;1&lt;/TD&gt;&lt;TD width="93.5px"&gt;4&lt;/TD&gt;&lt;TD width="148.438px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;After adding&amp;nbsp;"stats values(score) as score by ip vuln"&amp;nbsp; above the current stats ip,&lt;BR /&gt;count(vuln) no longer calculated the count of non distinct/original vuln&amp;nbsp; &amp;nbsp;(7=&amp;gt;3,&amp;nbsp; 4=&amp;gt;3)&lt;BR /&gt;sum(score) no longer calculated the count of non distinct/original score&amp;nbsp; (23=&amp;gt;10, 10=&amp;gt;5)&lt;/P&gt;&lt;TABLE width="720px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="58.7188px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;&lt;STRONG&gt;dc(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="151.625px" height="25px"&gt;&lt;STRONG&gt;dc(vuln) score &amp;gt; 0&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="97.5px" height="25px"&gt;&lt;STRONG&gt;count(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="147.094px" height="25px"&gt;&lt;STRONG&gt;sum(score)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="191.062px" height="25px"&gt;&lt;STRONG&gt;sum (dc(vuln) score &amp;gt; 0)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58.7188px" height="25px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151.625px" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="97.5px" height="25px"&gt;*3&lt;/TD&gt;&lt;TD width="147.094px" height="25px"&gt;*10&lt;/TD&gt;&lt;TD width="191.062px" height="25px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58.7188px" height="25px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151.625px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="97.5px" height="25px"&gt;*3&lt;/TD&gt;&lt;TD width="147.094px" height="25px"&gt;*5&lt;/TD&gt;&lt;TD width="191.062px" height="25px"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;This is what I would like to have&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="717px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="58px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;&lt;STRONG&gt;dc(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="151px" height="25px"&gt;&lt;STRONG&gt;dc(vuln) score &amp;gt; 0&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="97px" height="25px"&gt;&lt;STRONG&gt;count(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="147px" height="25px"&gt;&lt;STRONG&gt;sum(score)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="191px" height="25px"&gt;&lt;STRONG&gt;sum (dc(vuln) score &amp;gt; 0)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58px" height="25px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151px" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="97px"&gt;7&lt;/TD&gt;&lt;TD width="147px"&gt;23&lt;/TD&gt;&lt;TD width="191px" height="25px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58px" height="25px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="97px"&gt;4&lt;/TD&gt;&lt;TD width="147px"&gt;10&lt;/TD&gt;&lt;TD width="191px" height="25px"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Thu, 02 Nov 2023 19:35:57 GMT</pubDate>
    <dc:creator>LearningGuy</dc:creator>
    <dc:date>2023-11-02T19:35:57Z</dc:date>
    <item>
      <title>How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667079#M228853</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;How to calculate sum of a field based on other distinct field?&lt;BR /&gt;For example: How to find sum for score of distinct vulnerability (exclude 0) group by ip?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Before calculation&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="305"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="85"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="104"&gt;&lt;STRONG&gt;vuln&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="116"&gt;&lt;STRONG&gt;score&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln2&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln2&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln2&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln3&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;vuln3&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2.2.2.2&lt;/TD&gt;&lt;TD&gt;vuln1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2.2.2.2&lt;/TD&gt;&lt;TD&gt;vuln4&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2.2.2.2&lt;/TD&gt;&lt;TD&gt;vuln5&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2.2.2.2&lt;/TD&gt;&lt;TD&gt;vuln5&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;After calculation&lt;BR /&gt;&lt;/STRONG&gt;1.1.1.1:&amp;nbsp; &amp;nbsp;sum&amp;nbsp; (vuln 2 [score]) + sum(vuln 3 [score])&amp;nbsp; = 3 + 7 = 10&lt;BR /&gt;2.2.2.2&amp;nbsp; : sum (vuln 5 [score]) = 5&amp;nbsp;&lt;/P&gt;&lt;TABLE width="307px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="69.9219px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="236.078px" height="25px"&gt;&lt;STRONG&gt;sum (score of distinct vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="69.9219px" height="25px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="236.078px" height="25px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="69.9219px" height="25px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="236.078px" height="25px"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 02 Nov 2023 02:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667079#M228853</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-02T02:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667081#M228855</link>
      <description>&lt;P&gt;Do it in two steps just like you illustrated manually.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(score) as score by vuln ip
| stats sum(score) by ip&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an emulation of your sample data to compare with real data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="ip,vuln,score   
1.1.1.1,vuln1,0 
1.1.1.1,vuln1,0 
1.1.1.1,vuln2,3 
1.1.1.1,vuln2,3 
1.1.1.1,vuln2,3 
1.1.1.1,vuln3,7 
1.1.1.1,vuln3,7 
2.2.2.2,vuln1,0 
2.2.2.2,vuln4,0 
2.2.2.2,vuln5,5 
2.2.2.2,vuln5,5"
``` data emulation ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This emulation will give&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;sum(score)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1.1.1.1&lt;/TD&gt;&lt;TD&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2.2.2.2&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 02 Nov 2023 04:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667081#M228855</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-11-02T04:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667118#M228865</link>
      <description>&lt;LI-CODE lang="markup"&gt;| stats values(score) as score by ip vuln
| stats dc(eval(if(score &amp;gt; 0,vuln,null()))) as dc_gt_0 dc(vuln) as dc_all sum(score) as total_score by ip&lt;/LI-CODE&gt;&lt;P&gt;As also shown &lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-calculate-distinct-count-with-condition/m-p/667106/highlight/true#M228863" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 09:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667118#M228865</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-02T09:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667206#M228888</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Thank you so much for your help&lt;BR /&gt;&lt;STRONG&gt;Is it possible to do it in one stats, instead of two, so I can keep my previous original calculation?&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;I currently have stats ip with the following result&lt;/P&gt;&lt;TABLE width="529px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="59.9844px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="74.9375px"&gt;&lt;STRONG&gt;dc(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="151.141px"&gt;&lt;STRONG&gt;dc(vuln) score &amp;gt; 0&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="93.5px"&gt;&lt;STRONG&gt;count(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="148.438px"&gt;&lt;STRONG&gt;sum(score)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="59.9844px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="74.9375px"&gt;3&lt;/TD&gt;&lt;TD width="151.141px"&gt;2&lt;/TD&gt;&lt;TD width="93.5px"&gt;7&lt;/TD&gt;&lt;TD width="148.438px"&gt;23&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="59.9844px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="74.9375px"&gt;3&lt;/TD&gt;&lt;TD width="151.141px"&gt;1&lt;/TD&gt;&lt;TD width="93.5px"&gt;4&lt;/TD&gt;&lt;TD width="148.438px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;After adding&amp;nbsp;"stats values(score) as score by ip vuln"&amp;nbsp; above the current stats ip,&lt;BR /&gt;count(vuln) no longer calculated the count of non distinct/original vuln&amp;nbsp; &amp;nbsp;(7=&amp;gt;3,&amp;nbsp; 4=&amp;gt;3)&lt;BR /&gt;sum(score) no longer calculated the count of non distinct/original score&amp;nbsp; (23=&amp;gt;10, 10=&amp;gt;5)&lt;/P&gt;&lt;TABLE width="720px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="58.7188px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;&lt;STRONG&gt;dc(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="151.625px" height="25px"&gt;&lt;STRONG&gt;dc(vuln) score &amp;gt; 0&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="97.5px" height="25px"&gt;&lt;STRONG&gt;count(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="147.094px" height="25px"&gt;&lt;STRONG&gt;sum(score)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="191.062px" height="25px"&gt;&lt;STRONG&gt;sum (dc(vuln) score &amp;gt; 0)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58.7188px" height="25px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151.625px" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="97.5px" height="25px"&gt;*3&lt;/TD&gt;&lt;TD width="147.094px" height="25px"&gt;*10&lt;/TD&gt;&lt;TD width="191.062px" height="25px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58.7188px" height="25px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151.625px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="97.5px" height="25px"&gt;*3&lt;/TD&gt;&lt;TD width="147.094px" height="25px"&gt;*5&lt;/TD&gt;&lt;TD width="191.062px" height="25px"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;This is what I would like to have&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="717px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="58px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;&lt;STRONG&gt;dc(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="151px" height="25px"&gt;&lt;STRONG&gt;dc(vuln) score &amp;gt; 0&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="97px" height="25px"&gt;&lt;STRONG&gt;count(vuln)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="147px" height="25px"&gt;&lt;STRONG&gt;sum(score)&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="191px" height="25px"&gt;&lt;STRONG&gt;sum (dc(vuln) score &amp;gt; 0)&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58px" height="25px"&gt;1.1.1.1&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151px" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="97px"&gt;7&lt;/TD&gt;&lt;TD width="147px"&gt;23&lt;/TD&gt;&lt;TD width="191px" height="25px"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="58px" height="25px"&gt;2.2.2.2&lt;/TD&gt;&lt;TD width="73px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="151px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="97px"&gt;4&lt;/TD&gt;&lt;TD width="147px"&gt;10&lt;/TD&gt;&lt;TD width="191px" height="25px"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 02 Nov 2023 19:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667206#M228888</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-02T19:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667241#M228898</link>
      <description>&lt;LI-CODE lang="markup"&gt;| stats values(score) as score sum(score) as vuln_score count by ip vuln
| stats dc(eval(if(score &amp;gt; 0,vuln,null()))) as dc_gt_0 dc(vuln) as dc_all sum(score) as total_score sum(vuln_score) as vuln_score sum(count) as count by ip&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:25:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667241#M228898</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-02T22:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667253#M228901</link>
      <description>&lt;P&gt;I tested your suggestion and it worked.&lt;BR /&gt;I accepted this as solution.&lt;BR /&gt;I appreciate your help. Thank you so much.&lt;BR /&gt;&lt;BR /&gt;So, it's not possible in Splunk to make it only with 1 stats, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 05:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667253#M228901</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-03T05:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667254#M228902</link>
      <description>&lt;P&gt;Thank you so much for your assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 05:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667254#M228902</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-11-03T05:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate sum of a field based on other distinct field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667271#M228911</link>
      <description>&lt;P&gt;Correct, it is not possible in one go because you are effectively grouping by two different dimension sets.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 09:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-sum-of-a-field-based-on-other-distinct-field/m-p/667271#M228911</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-03T09:30:46Z</dc:date>
    </item>
  </channel>
</rss>

