Dashboards & Visualizations

Sum with multivalue token

Shaft
Explorer

How to sum the values of a multivalue token in Simple XML?

Let's say you have a mv token named test1 with values of: 1,2,3

How to achieve something like:
<eval token="test2">sum($test1$)</eval>

Thanks!

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

One way might be to use relative_time which will interpret strings

<eval token="test2">if(mvcount($test1$)>1,relative_time(0,"@s+".mvjoin($test1$,"s+")."s"),$test1$)</eval>

Be aware that is $test1$ is from something like a multiselect dropdown, you may need to use $form.test1$ to get the multivalue version of the field rather than the concatenated version.

View solution in original post

0 Karma

Shaft
Explorer

What a trick! Well done....

ITWhisperer
SplunkTrust
SplunkTrust

One way might be to use relative_time which will interpret strings

<eval token="test2">if(mvcount($test1$)>1,relative_time(0,"@s+".mvjoin($test1$,"s+")."s"),$test1$)</eval>

Be aware that is $test1$ is from something like a multiselect dropdown, you may need to use $form.test1$ to get the multivalue version of the field rather than the concatenated version.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...