Splunk Dev

issue in sum chart and addcoltotals

ND
Path Finder

Hi All,

I want to show sum of field by year(2019, 2020, 2021)

i am using query:

|inputlookup abc.csv | eval _time=strptime('date1',"%Y-%m-%d")| eval year= strftime(_time,"%Y")  | chart sum(com) as com by field1, year| addcoltotals

o/p:

field1 com 2019 2020 2021 

for this total for 2020 is correct but facing issue for 2019 & 2021

please help me to get correct solution for this.

Thank,

ND

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

What "issue" are you facing? Are the rows incorrectly associated with proper years? Is the sum incorrectly counted?

Oh, and instead of strptime and strftime, you could just do

| eval year=substr(date1,1,4)

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What "issue" are you facing? Are the rows incorrectly associated with proper years? Is the sum incorrectly counted?

Oh, and instead of strptime and strftime, you could just do

| eval year=substr(date1,1,4)
0 Karma

ND
Path Finder

yes ,the sum incorrectly counted, for  year 2019 and 202. but sum for 2020 is correctly counted.

the data is correctly associated 

| eval year=substr(date1,1,4) thanks will update this.
0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...