Splunk Search

Cumulate counts in timechart for sw-rollout

yAlff
Path Finder

Hi,

I'm looking for a function to cumulate values in a timechart, so I can see a real-time development of a software roll-out - distincted by a UID. The result should look as a ramp.

My search string looks like this:

sourcetype="foo" devicetype="Bob" | timechart dc(uid) as totale by sw | addtotals

This table as an example of the desired results:

Time   # events   w/ new sw    cumulated
Day 1       128         128          128
Day 2       230         102          230
Day 3       220          78          308

So at Day 3 in the example, there are 308 devices with the new software AND it is clear to see, that it doesn't depend primary on how many events where registered.

I think I have to extract the UIDs from one day into a file, to compare them with the UIDs from the next day.

I just tried accum and streamstat, but nothing fits my expectations.

Is there any possibility to solve the problem? This problem is driving me crazy...

Regards 😉

jtrucks
Splunk Employee
Splunk Employee

Perhaps try:

sourcetype="foo" devicetype="Bob" | timechart dc(uid) as totale by sw | addtotals sw

addtotals should then narrow the calculated results to just that field's data.

--
Jesse Trucks
Minister of Magic
0 Karma

yAlff
Path Finder

Thanks, but it just adds the field totals and now the results are zero - over all time.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Do you have a small sample set of data?

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...