I'm using the addtotals command to sum values I have in a given column of a report. The total shows up just like I want however I'm trying to figure out how to put a descriptive name to it in a specific position. Here's my table that my search string produces:
Parameter Breakdown count
Reports with RF Paramaters values as n/a 6
Reports with RxPwr out of spec 2
Reports with TxPwr value out of spec 8
16
Here are the last few lines of my search string:
| chart count by RFFailure_Stats
| rename RFFailure_Stats AS "Parameter Breakdown"
| addtotals col=t row=f
What I'd like to see is the following:
Parameter Breakdown count
Reports with RF Paramaters values as n/a 6
Reports with RxPwr out of spec 2
Reports with TxPwr value out of spec 8
Total Count 16 <<<<<<<
If I use
| addtotals col=t row=f labelfield=Total_count
I get the following:
Parameter Breakdown count Total_count
Reports with RF Paramaters values as n/a 6
Reports with RxPwr out of spec 2
Reports with TxPwr value out of spec 8
16 Total
Is there a way to accomplish what I am after?
Try this
...your base search...| chart count by RFFailure_Stats
| addtotals col=t row=f labelfield=RFFailure_Stats label="Total count"
| rename RFFailure_Stats AS "Parameter Breakdown"
Try this
...your base search...| chart count by RFFailure_Stats
| addtotals col=t row=f labelfield=RFFailure_Stats label="Total count"
| rename RFFailure_Stats AS "Parameter Breakdown"
I have it working now. Thanks again for the suggestion.
Please mark this as answered in this case - thx
Using somesoni2 example worked over here:
index=_internal | stats sum(bytes) as bytes by user | addtotals col=t row=f fieldname=bytes label="Total Bytes" labelfield="user" | rename user as "Splunk Users"
Thanks for your response. Tried what you suggested and got the same result.