<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to add the total in GB in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697311#M236895</link>
    <description>&lt;P&gt;I need to add the total GB.&amp;nbsp; Please let me know how to add the over all total.&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Index&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Source-Type&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; GB&lt;/DIV&gt;&lt;DIV&gt;aws_vpcflow&amp;nbsp; &amp;nbsp;- aws:vpcflow&amp;nbsp; &amp;nbsp; 26192.00305&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp;aws:cloudwatchlogs:vpcflow 32.695269&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;windows&amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp;windows:fluentd&amp;nbsp; &amp;nbsp; &amp;nbsp;19939.02727&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp;windows&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9713.832884&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp;WinEventLog:Security&amp;nbsp; &amp;nbsp;8.928759&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 26 Aug 2024 14:49:37 GMT</pubDate>
    <dc:creator>harishsplunk7</dc:creator>
    <dc:date>2024-08-26T14:49:37Z</dc:date>
    <item>
      <title>how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697311#M236895</link>
      <description>&lt;P&gt;I need to add the total GB.&amp;nbsp; Please let me know how to add the over all total.&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Index&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Source-Type&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; GB&lt;/DIV&gt;&lt;DIV&gt;aws_vpcflow&amp;nbsp; &amp;nbsp;- aws:vpcflow&amp;nbsp; &amp;nbsp; 26192.00305&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp;aws:cloudwatchlogs:vpcflow 32.695269&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;windows&amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp;windows:fluentd&amp;nbsp; &amp;nbsp; &amp;nbsp;19939.02727&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp;windows&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 9713.832884&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp;WinEventLog:Security&amp;nbsp; &amp;nbsp;8.928759&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 26 Aug 2024 14:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697311#M236895</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2024-08-26T14:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697312#M236896</link>
      <description>&lt;P&gt;You can use&amp;nbsp;addtotals as below -&amp;nbsp;&lt;/P&gt;&lt;P&gt;| addtotals col=t row=f labelfield=index label="Overall Total"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please accept the solution and hit Karma, if this helps!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 15:04:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697312#M236896</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-08-26T15:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697314#M236897</link>
      <description>&lt;P class="lia-align-left"&gt;If i use the&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| addtotals col=t row=f labelfield=Index label="Overall Total"&lt;/LI-CODE&gt;
&lt;P class="lia-align-left"&gt;, I am getting incorrect total result ,&lt;BR /&gt;becuase one index and multiple sourcetype values are there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 15:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697314#M236897</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2024-08-26T15:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697323#M236899</link>
      <description>&lt;P&gt;Please share your actual events (anonymised appropriately) in a codeblock&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 15:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697323#M236899</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-26T15:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697325#M236900</link>
      <description>&lt;P&gt;Please find teh below sample values&lt;/P&gt;&lt;TABLE border="1" width="99.87012987012986%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="27.4025974025974%"&gt;Index&lt;/TD&gt;&lt;TD width="55.97402597402598%"&gt;Source-Type&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;GB&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="27.4025974025974%"&gt;aws_vpcflow&lt;/TD&gt;&lt;TD width="55.97402597402598%"&gt;aws:vpcflow&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="55.97402597402598%"&gt;aws:cloudwatchlogs:vpcflow&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="27.4025974025974%"&gt;windows&lt;/TD&gt;&lt;TD width="55.97402597402598%"&gt;windows:fluentd&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;30&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="55.97402597402598%"&gt;windows&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;40&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="55.97402597402598%"&gt;WinEventLog:Security&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;50&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="27.4025974025974%"&gt;cloud&amp;nbsp;&lt;/TD&gt;&lt;TD width="55.97402597402598%"&gt;cloud_watch&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;60&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="55.97402597402598%"&gt;aws_cloud&lt;/TD&gt;&lt;TD width="16.493506493506494%"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 26 Aug 2024 15:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697325#M236900</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2024-08-26T15:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697326#M236901</link>
      <description>&lt;P&gt;What search did you use to get this table?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2024 16:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697326#M236901</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-26T16:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697328#M236902</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal source=/opt/splunk/var/log/splunk/license_usage.log type=Usage
| stats sum(b) as bytes by st , idx
| eval GB=round(bytes/(1024*1024*1024),6)
| table st, idx, GB
| sort -GB
| eventstats sum(GB) as total

| eval Percentage=round((GB/total)*100,6)
| rename st as SourceType
| rename idx as Index

| stats list(SourceType) as "Source-Type", list(GB) as GB by Index
| addtotals col=t row=f labelfield=Index label="Overall Total"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 26 Aug 2024 18:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697328#M236902</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2024-08-26T18:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697329#M236903</link>
      <description>&lt;P&gt;Try switching the last two lines&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| addtotals col=t row=f labelfield=Index label="Overall Total"
| stats  list(SourceType) as "Source-Type", list(GB) as GB by Index&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 26 Aug 2024 16:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697329#M236903</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-26T16:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to add the total in GB</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697330#M236904</link>
      <description>&lt;P&gt;Or&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats  list(SourceType) as "Source-Type", list(GB) as GB by Index
| appendpipe
    [| stats sum(GB) as GB
    | eval Index="Overall Total"]&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 26 Aug 2024 16:20:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-add-the-total-in-GB/m-p/697330#M236904</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-26T16:20:28Z</dc:date>
    </item>
  </channel>
</rss>

