Splunk Cloud Platform

How to use stats sum and stats count by in Single command?

kalaiyarasi
Loves-to-Learn Lots

Hi,

I have below fields in which i need to display the count of each field value
|eval TotalApps=if(match('Type'="NTB"),"1","0")

|eval InProgress=if(Type= "NTB" AND isnull(date),"1","0")

|eval Submitted=if(Type= "NTB" AND isnotnull(date),"1","0")
|eval Apps_Submitted=if(match('Myinfo_Used',"1"),'REASON_CD',"0")
|stats count by Apps_Submitted

getting results as

COPS   1

CMS   2

FCO   3

but requirement is

|stats sum(TotalApps) as TotalApps sum(InProgress) as InProgress sum(Submitted) as  Submitted (along with the AppsSubmitted count of each field value)

Eg:

TotalApps    10

InProgress   5

Submitted   5

AppsSubmitted  5

COPS       1

CMS         2

FCO          3

Labels (1)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some sample events in a code block </> so we can see what you are dealing with.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...