Splunk Search

Group data 'n' rows at a time

nikita012
New Member

I have 40 rows in my data with fields Date, Total. I want to add the values of Total for each 5 days. How can I group data 5 rows at a time?

0 Karma
1 Solution

renjith_nair
Legend

@nikita012,

Try this,

"your current search"
|streamstats count as rowno|eval _fives=if((rowno-1)%5==0,1,0)
|accum _fives as group|eventstats sum(total) by group

you may replace eventstats with stats if you do not want other fields

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

@nikita012,

Try this,

"your current search"
|streamstats count as rowno|eval _fives=if((rowno-1)%5==0,1,0)
|accum _fives as group|eventstats sum(total) by group

you may replace eventstats with stats if you do not want other fields

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...