<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Complete a timechart with a total column in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41621#M9639</link>
    <description>&lt;P&gt;I'm sorry, I did not succeed in this way.&lt;BR /&gt;
I'm close to the goal with : &lt;/P&gt;

&lt;P&gt;index="jdbc" sourcetype="BD_PANDORA_PROD"&lt;BR /&gt;&lt;BR /&gt;
| timechart span=1mon limit=16 eval(max(nbr_teams)) by directorate &lt;BR /&gt;
| appendcols &lt;BR /&gt;
[search index="jdbc" sourcetype="BD_PANDORA_PROD" | timechart span=1mon eval(round((sum(nbr_teams)/(count(nbr_teams)/16)),0)) AS TOTAL by Time ]&lt;BR /&gt;
| rename _time AS Time | eval Time=strftime(Time, "%B")&lt;/P&gt;

&lt;P&gt;But this new column is called "Null" and stay between others column instead of being at the end...&lt;BR /&gt;
But I think, they is a better solution for my huge eval expression&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:46:16 GMT</pubDate>
    <dc:creator>Emilien</dc:creator>
    <dc:date>2020-09-28T11:46:16Z</dc:date>
    <item>
      <title>Complete a timechart with a total column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41618#M9636</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I got a timechart with 16 values automatically generated. But I want to have another column to show the sum of all these values.&lt;/P&gt;

&lt;P&gt;This is my search : &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;index="jdbc"&lt;BR /&gt;
sourcetype="BD_PANDORA_PROD" |&lt;BR /&gt;
timechart span=1mon limit=16&lt;BR /&gt;
eval(max(nbr_teams)) by directorate  |&lt;BR /&gt;
rename _time AS Time | eval&lt;BR /&gt;
Time=strftime(Time, "%B")&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;A href="http://imageshack.us/photo/my-images/502/totalresult2.jpg/" target="_blank"&gt;http://imageshack.us/photo/my-images/502/totalresult2.jpg/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Have a look at the only result I  was able to make  : &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;index="jdbc"&lt;BR /&gt;
sourcetype="BD_PANDORA_PROD" |&lt;BR /&gt;
timechart span=1mon limit=16&lt;BR /&gt;
eval(max(nbr_teams)) by directorate  |&lt;BR /&gt;
append [search index="jdbc"&lt;BR /&gt;
sourcetype="BD_PANDORA_PROD" |&lt;BR /&gt;
timechart&lt;BR /&gt;
eval(round((sum(nbr_teams)/(count(nbr_teams)/16)),0))&lt;BR /&gt;
AS TOTAL by Time ]&lt;/P&gt;

&lt;P&gt;| rename _time AS Time | eval&lt;BR /&gt;
Time=strftime(Time, "%B")&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;But this is not what I expected…&lt;BR /&gt;
&lt;A href="http://imageshack.us/photo/my-images/856/totalresult1.jpg/" target="_blank"&gt;http://imageshack.us/photo/my-images/856/totalresult1.jpg/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thank you for helping me.&lt;/P&gt;

&lt;P&gt;Emilien&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41618#M9636</guid>
      <dc:creator>Emilien</dc:creator>
      <dc:date>2020-09-28T11:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Complete a timechart with a total column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41619#M9637</link>
      <description>&lt;P&gt;Just as an aside, you can do "convert timeformat=%B ctime(_time) AS Time" instead of the rename / eval.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2012 15:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41619#M9637</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-05-02T15:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Complete a timechart with a total column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41620#M9638</link>
      <description>&lt;P&gt;In the past I've used &lt;CODE&gt;eventstats&lt;/CODE&gt; to calculate a total field for a search.  Unfortunately, the place to apply it doesn't jump out at me from your example.&lt;/P&gt;

&lt;P&gt;Maybe something like&lt;/P&gt;

&lt;PRE&gt;
index="jdbc"
sourcetype="BD_PANDORA_PROD"  |
stats max(nbr_teams) AS max by directorate |
eventstats sum(max) AS Total | 
timechart ...
&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 May 2012 15:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41620#M9638</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-05-02T15:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Complete a timechart with a total column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41621#M9639</link>
      <description>&lt;P&gt;I'm sorry, I did not succeed in this way.&lt;BR /&gt;
I'm close to the goal with : &lt;/P&gt;

&lt;P&gt;index="jdbc" sourcetype="BD_PANDORA_PROD"&lt;BR /&gt;&lt;BR /&gt;
| timechart span=1mon limit=16 eval(max(nbr_teams)) by directorate &lt;BR /&gt;
| appendcols &lt;BR /&gt;
[search index="jdbc" sourcetype="BD_PANDORA_PROD" | timechart span=1mon eval(round((sum(nbr_teams)/(count(nbr_teams)/16)),0)) AS TOTAL by Time ]&lt;BR /&gt;
| rename _time AS Time | eval Time=strftime(Time, "%B")&lt;/P&gt;

&lt;P&gt;But this new column is called "Null" and stay between others column instead of being at the end...&lt;BR /&gt;
But I think, they is a better solution for my huge eval expression&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41621#M9639</guid>
      <dc:creator>Emilien</dc:creator>
      <dc:date>2020-09-28T11:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Complete a timechart with a total column</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41622#M9640</link>
      <description>&lt;P&gt;Stop searching, this is very simple, just add "| addtotals"&lt;/P&gt;

&lt;P&gt;it looks like this code : &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;index="jdbc"&lt;BR /&gt;
sourcetype="BD_PANDORA_PROD"  |&lt;BR /&gt;
timechart span=1mon limit=16&lt;BR /&gt;
eval(max(nbr_teams)) by directorate |&lt;BR /&gt;
addtotals | rename _time AS Time |&lt;BR /&gt;
eval Time=strftime(Time, "%B")&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;And it's done !&lt;/P&gt;

&lt;P&gt;Enjoy !&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Complete-a-timechart-with-a-total-column/m-p/41622#M9640</guid>
      <dc:creator>Emilien</dc:creator>
      <dc:date>2020-09-28T11:46:21Z</dc:date>
    </item>
  </channel>
</rss>

