Getting Data In

how to sum numbers with space in them

halperkins
New Member

I have a field called size that takes the form:
1 2 3 4

I want to find someway to evaluate size so that is sums all the numbers.
for example, eval totalsize = (size) would evaluate to 10.

basically my field size is a collection of sizes, and i want to sum it up for the total size.
stats sum is not an option, since it sums it will sum everything over every single event.I need it to sum one event at a time.

to be very specific, here is a picture of what i am going for:
http://tinypic.com/r/2pru4h0/6

how do i get totalsize?

thanks a bunch

EDIT:
ehh
i tried something like that
unfortunately my host fields arent unique
What im doing is getting file sizes from hosts at different times.
So for example, host1 could have a different number of files at each event, and i only want to get the sum at each particular event

Is there any other way?

0 Karma

lguinn2
Legend

This solution assumes that the numbers are separated by a single space, and that the host field is unique:

yoursearchhere
| eval newNums=split(size," ")
| mvexpand newNums
|  stats sum(newNums) as TotalSize by host
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...