Splunk Search

Can you help me with the following search in Splunk?

vumanhtai
Path Finder

Hi Team Splunk!
alt text

How can i do this?

Thanks!

0 Karma

nagarjuna280
Communicator

| table src_ip dest_ip megabyte | addcoltotals megabyte labelfield=total(megabytes) label="src_ip"

0 Karma

vumanhtai
Path Finder

thank you!
but result is not i want

0 Karma

dflodstrom
Builder

You can use 'addcoltotals' to display a total for your megabyte column. Add this to the end of your search | addcoltotals labelfield=dest_ip label= "total(megabyte)" megabyte It won't display like you're showing with a merged cell though.

0 Karma

vumanhtai
Path Finder

thank you!
but result is not i want

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...