Splunk Search

Adding results, fields from two different queries

Influencer

I have two completely different queries which of them output fields like below

The output of the fields will be just one value

Query 1 -        ...|table total1
Query 2 -        ...|table total2

Now I want to add these two fields total1 and total2 and display it.

How can I achieve this in a single query?

Tags (2)
0 Karma
1 Solution

Legend

Try appendcols

query1 
| appendcols [ search query2]
| eval grandTotal = total1 + total2

View solution in original post

Legend

Try appendcols

query1 
| appendcols [ search query2]
| eval grandTotal = total1 + total2

View solution in original post

Influencer

It did.. Thanks!

0 Karma

Influencer

Perfect. Thanks much!

Will it work the same way for 3 queries? My actual requirement was for 3 queries. I'm yet to try that. Hope it works 🙂

0 Karma