Getting Data In

how to sum numbers with space in them

halperkins
New Member

I have a field called size that takes the form:
1 2 3 4

I want to find someway to evaluate size so that is sums all the numbers.
for example, eval totalsize = (size) would evaluate to 10.

basically my field size is a collection of sizes, and i want to sum it up for the total size.
stats sum is not an option, since it sums it will sum everything over every single event.I need it to sum one event at a time.

to be very specific, here is a picture of what i am going for:
http://tinypic.com/r/2pru4h0/6

how do i get totalsize?

thanks a bunch

EDIT:
ehh
i tried something like that
unfortunately my host fields arent unique
What im doing is getting file sizes from hosts at different times.
So for example, host1 could have a different number of files at each event, and i only want to get the sum at each particular event

Is there any other way?

0 Karma

lguinn2
Legend

This solution assumes that the numbers are separated by a single space, and that the host field is unique:

yoursearchhere
| eval newNums=split(size," ")
| mvexpand newNums
|  stats sum(newNums) as TotalSize by host
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...