Splunk Enterprise

How to create a customized query for table?

mahesh27
Communicator

 table 1:

_time allocation website quantity failed impacted_allocations
2022-10-12 09:00 CMD www.asd.com 100 20 5
2022-10-13 10:00 CMD www.asco.com 200 30 10
2022-10-25 15:00 KMD www.hyg.com 300 40 12
2022-11-01 18:00 KMD www.sts.com 400 50 18

 

table2:

Presently I have table 1 but the requirement is  last column called "impacted_allocations" should get added up and display the added number
for example: For allocation we have 2 rows as "CMD" so for  CMD -impacted_allocation values should get added up(5+10=15) and show as 15 in the table.
the same goes with the KMD(12+18=30) 30 should display in my table as shown below.

_time allocation website quantity failed impacted_allocations
2022-10-12 09:00 CMD www.asd.com 100 20 15
2022-10-13 10:00 CMD www.asco.com 200 30  
2022-10-25 15:00 KMD www.hyg.com 300 40 30
2022-11-01 18:00 KMD www.sts.com 400 50  
Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eventstats sum(impacted_allocations) as total_impacted_allocations by allocation

vishwa
Path Finder

@ITWhisperer , thank you for the query, it helped.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...