... | table Field Count | sort 0 Field
For example, we have
Field | Count |
n1 | 1 |
n2 | 10 |
n3 | 100 |
n4 | 1000 |
How can I make funnel like this?
Field | Count |
n1 | 1 |
n2 | 11 |
n3 | 111 |
n4 | 1111 |
Value of Funnel is equal to sum of previous value of Funnel and current value of Count.
Or the built-in command accum
specifically for this purpose;
... | accum count
http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Accum
/K
Append this:
... | streamstats sum(Count) as Count