Hi folks,
I'm trying to merge events that share a common keyword value, with the mvcombine. The problem is it just lists the same value multiple times; I want it to add them up.
The search is relatively normal, but cumbersome to put here, so I will post just a bit:
... | table HOST percentcomplete | mvcombine percentcomplete | sort HOST
It combines the fields but outputs them as:
exch-svr-04 1.45
1.45
1.45
1.45
1.45
1.45
1.45
1.45
exch-svr-54 2.54
2.54
2.54
2.54
2.54
2.54
I want it to just add up those columns. Is there a simple way to do this?
Edit: I looked at some more results and it looks like my implementation of the mvcombine is also mergin my hosts. So I may be going about this the wrong way.
How about
... | stats sum(percentcomplete) by HOST | sort HOST
instead of
... | table HOST percentcomplete | mvcombine percentcomplete | sort HOST