Splunk Search

AddColTotals

xvxt006
Contributor

Hi, I want to get the count of errors. So i have a query to get the count by status where status is greater than 400. When i use addcoltotals, it is thinking status as a column and hence it is giving the total for both. How can i get that?

/Current
No status count
1 200 26
2 302 57
3 502 83

Expected

No status count
1 200 26
2 302 57
3 Total 83

sourcetype=access_combined_wcookie host="qqqq*" uri=/checklogin* status>400 | stats count by status | addcoltotals label=Total labelfield=status

Tags (1)
0 Karma
1 Solution

bmunson_splunk
Splunk Employee
Splunk Employee

You should be able to just name the fields you want totals for.

sourcetype=access_combined_wcookie host="qqqq" uri=/checklogin status>400 | stats count by status | addcoltotals count label=Total labelfield=status

View solution in original post

xvxt006
Contributor

Thank you !!! This worked fine.

0 Karma

bmunson_splunk
Splunk Employee
Splunk Employee

You should be able to just name the fields you want totals for.

sourcetype=access_combined_wcookie host="qqqq" uri=/checklogin status>400 | stats count by status | addcoltotals count label=Total labelfield=status

aholzer
Motivator

I don't think it's possible to exclude with addColTotals, but you should be able to with addTotals. Here's the documentation: http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Addtotals

Your search would look like this:
sourcetype=access_combined_wcookie host="qqqq" uri=/checklogin status>400 | stats count by status | addTotals col=t label=Total labelfield=status count

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...