Dashboards & Visualizations

addtotals result move to the top row

viktoriiants
Explorer

The query produces multiple pages of results. How do I move the total to the top (first) row for convenience?

 

search query | eval dayOfWeek=strftime(_time, "%A"), date=strftime(_time, "%Y-%m-%d") | eval dayNum=case(dayOfWeek=="Sunday", 1, dayOfWeek=="Monday", 2, dayOfWeek=="Tuesday", 3, dayOfWeek=="Wednesday", 4, dayOfWeek=="Thursday", 5, dayOfWeek=="Friday", 6, dayOfWeek=="Saturday", 7) | stats count as "Session count" by dayOfWeek, date | addtotals col=t row=f label="Month total" |sort date desc

 

Labels (2)
0 Karma
1 Solution

danspav
SplunkTrust
SplunkTrust

Hi @viktoriiants.,

How about something like this:

index=_internal 
| eval dayOfWeek=strftime(_time, "%A"), date=strftime(_time, "%Y-%m-%d") 
| eval dayNum=tonumber(strftime(_time,"%w")) + 1 ``` 1=Sunday, ..., 7=Saturday```
| stats count as "Session count" by dayOfWeek, date 
| addtotals col=t row=f
| eval sort = if(isnull(date),1,0)
| sort - sort + date 
| fields - sort

Here we're creating a new temporary field to sort on, where we set it to 1 for our total row, and 0 for all other rows. Then we sort by this column and the date column. Finally, we remove the "sort" column.

View solution in original post

danspav
SplunkTrust
SplunkTrust

Hi @viktoriiants.,

How about something like this:

index=_internal 
| eval dayOfWeek=strftime(_time, "%A"), date=strftime(_time, "%Y-%m-%d") 
| eval dayNum=tonumber(strftime(_time,"%w")) + 1 ``` 1=Sunday, ..., 7=Saturday```
| stats count as "Session count" by dayOfWeek, date 
| addtotals col=t row=f
| eval sort = if(isnull(date),1,0)
| sort - sort + date 
| fields - sort

Here we're creating a new temporary field to sort on, where we set it to 1 for our total row, and 0 for all other rows. Then we sort by this column and the date column. Finally, we remove the "sort" column.

viktoriiants
Explorer

Thank you! It did help 

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello, Just checking through if the issue was resolved or you have any further questions? 

0 Karma

viktoriiants
Explorer

Thank you

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Hello @viktoriiants, How about sorting it by 'Session count' before date desc?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...