Knowledge Management

How to search sum rows by column?

politrons
Explorer

Having this initial query I obtain a list of results order by Consumer, and pod

messages_number container_name="pol-sms-amh-throttler" | stats avg(messages_number) as consumer_node by Consumer, pod

 

splunk_1.PNG

 

Then I append a second stats where I want to sum all the values of pods by Consumer

messages_number container_name="pol-sms-amh-throttler" | stats avg(messages_number) as consumer_node by Consumer, pod | stats sum(consumer_node) as AvgConsumption by Consumer limit=0

 

splunk_2.PNG

Is this query correct and accurate about what I'm want to achieve? 

 

Also I don't know how can I see the AvgConsumptions  in a visualization

Labels (3)

politrons
Explorer

 you're not doing the same thing.

If we have 3 pods that are producing messages_number 3,4,2. What I want to know is that all of them are producing 9.

But with your query it will produce just 4 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If you just want to sum them, try this

messages_number container_name="pol-sms-amh-throttler" | stats sum(messages_number) as TotalConsumption by Consumer limit=0

ITWhisperer
SplunkTrust
SplunkTrust

What you have will give you a number although I am not sure what significance it has - have you considered just doing it this way?

messages_number container_name="pol-sms-amh-throttler" | stats avg(messages_number) as AvgConsumption by Consumer limit=0
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...