Splunk Dev

Add Values from Rows

dfrench151
Explorer

Hello,

I'm trying to add values from rows. See the picture below. alt text

What I am pretty much trying to do is add the count from unconfirmed_down status to the up status. The thing is is that the unconfirmed_down status isn't always there depending on the source I am pulling from and could vary from month to month, so I need to have an exception included in case it is not there. I have though have saying add field 1 to field 2, but that could produce incorrect results if that particular status is not there...

0 Karma
1 Solution

niketn
Legend

@dfrench151 can you try the following?

index=<yourIndexName>
| eval status=if(status=="unconfirmed_down","up",status)
| stats count by status
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

niketn
Legend

@dfrench151 can you try the following?

index=<yourIndexName>
| eval status=if(status=="unconfirmed_down","up",status)
| stats count by status
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

dfrench151
Explorer

This only produced that status for up and count unfortunately

0 Karma

niketn
Legend

The above should move unconfirmed_down as up and remaining up and down status intact. So final sum should be only up and down status. Is your expectation different
?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

dfrench151
Explorer

Sorry about that. I re-ran that and it did what I needed. Thank you

niketn
Legend

No problem. Glad it worked!

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...