Splunk Search

Can you help me with an issue writing query and chart?

su_kumar
New Member

Hi,

I am facing an issue in writing a query.

Example:

Let's assume I have 2 groups such as :

  1)Group 1 has user 1, user 2, user 3
  2)Group 2 has user 4, user 5, user 6

I want to display in Group usage per user information and total usage group1 , group2 ..

example :
1)

Total Group 1 usage : 100 Mb (Application1: 70 Mbs, Application2: 30 Mbs)
======================================================================
User 1 usage : 40 Mb (Appl1: 25 Mbs, Appl2: 15 Mbs)
User 2 usage : 35 Mb (Application1: 25 Mbs, Application2: 10 Mbs)
User 3 usage : 25 Mb (Application1: 20 Mbs, Application2: 5 Mbs)

Here, Group1 has 3 users( user1 , user2, user2) and user1 usage 40 MB (for App1:25MB and App2:15MB) , user2 usage 35 MB (APP1 :25MB and App2:10MB) User3 usage 25MB(APP1:20MB and APP2:5MB).

I want to display Group per user report and total for each Group and create chart for total bandwidth over Group per user.

write below query for chart :

|chart sum(bytes) over app by Group

How do I write a query for a total for each group?

Tags (1)
0 Karma

renjith_nair
Legend

@su_kumar ,

Try,

|stats sum(bytes)  as sum_app by app ,Group|eventstats sum(sum_app) as total by Group
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...