Splunk Search

Sum of two fields

tej8
New Member

I have two fields "body.response.successfulItemsCount" & "body.successfulItemsCount". I need sum of total of these two fields.

I ran separate queries like this : 1. index= AND | chart sum("body.response.successfulItemsCount") as sum
2. index= AND ** | chart sum("body.successfulItemsCount") as sum

I got accurate result when i run these queries , but how to get total sum of results in one query? I tried this one but not working
index= AND | chart sum("body.response.successfulItemsCount" OR "body.successfulItemsCount") as sum

Tags (1)
0 Karma

whrg
Motivator

Hello @tej8,

Try something like this:

your base search
| stats sum("body.response.successfulItemsCount") AS sum1 sum("body.successfulItemsCount") AS sum2
| eval totalsum = sum1 + sum2
0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Announcing the General Availability of Splunk Enterprise Security 8.1!

We are pleased to announce the general availability of Splunk Enterprise Security 8.1. Splunk becomes the only ...

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...