<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sum up several fields with integer counts to one in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328583#M97811</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have several fields which should be summed up to one count. I tried the following but the field is not showing up (even with fields + fieldname).&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=otcs  sourcetype=OtcsSummaryTimings FunctionAction="doc.fetch" OR  FunctionAction="doc.Fetch" OR FunctionAction="fetch"   | eval sumFetch=doc.Fetch+doc.fetch+fetch | timechart span=7d count by FunctionAction
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The result only shows the fields without the calculated one. I unfortunately can't attach files (karma).&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2018 06:47:06 GMT</pubDate>
    <dc:creator>mhornste</dc:creator>
    <dc:date>2018-04-12T06:47:06Z</dc:date>
    <item>
      <title>sum up several fields with integer counts to one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328583#M97811</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have several fields which should be summed up to one count. I tried the following but the field is not showing up (even with fields + fieldname).&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=otcs  sourcetype=OtcsSummaryTimings FunctionAction="doc.fetch" OR  FunctionAction="doc.Fetch" OR FunctionAction="fetch"   | eval sumFetch=doc.Fetch+doc.fetch+fetch | timechart span=7d count by FunctionAction
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The result only shows the fields without the calculated one. I unfortunately can't attach files (karma).&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 06:47:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328583#M97811</guid>
      <dc:creator>mhornste</dc:creator>
      <dc:date>2018-04-12T06:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: sum up several fields with integer counts to one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328584#M97812</link>
      <description>&lt;P&gt;Can you try something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=otcs  sourcetype=OtcsSummaryTimings FunctionAction="doc.fetch" OR  FunctionAction="doc.Fetch" OR FunctionAction="fetch"  
| stats count(eval(FunctionAction="doc.fetch")) AS count_doc_fetch  count(eval(FunctionAction="doc.Fetch")) AS count_doc_Fetch count(eval(FunctionAction="fetch")) AS count_fetch by _time | eval sumFecth='count_doc_fetch'+'count_fetch'+'count_doc_Fetch'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 12 Apr 2018 06:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328584#M97812</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-12T06:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: sum up several fields with integer counts to one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328585#M97813</link>
      <description>&lt;P&gt;So, you have 3 slightly different types of events, each having the fetch value in a different field?&lt;/P&gt;

&lt;P&gt;An eval statement like that will not work at all, if some of the fields in it are missing, they will not automagically evaluate to 0 and still make the summation work.&lt;/P&gt;

&lt;P&gt;I would solve this by renaming the 3 different fields such that they have the same name in each event, and then simply doing a stats sum() on that.&lt;/P&gt;

&lt;P&gt;Also not sure what exactly you try to do with that timechart, as that doesn't reference the sumFetch field in any way???&lt;/P&gt;

&lt;P&gt;Even though you cannot attach files, you can still upload screenshots somewhere and put the URL in your question, right?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sum-up-several-fields-with-integer-counts-to-one/m-p/328585#M97813</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-04-12T07:57:23Z</dc:date>
    </item>
  </channel>
</rss>

