Splunk Search

How To Sum Hourly Column Results In A Separate Column

mark_groenveld
Path Finder

I am looking to sum up cumulative column totals by hour in a separate column.

Here is the search:

index=main CompletedEvent | bin _time span=1h | stats dc(clientid) as HourlyClients by _time

I would like there to be a 2nd result column that accumulates the 1st column by hour.  For example:  the result in row 2 of the 2nd column will be the sum of rows 1 and 2 in the 1st column, the result of row 3 of the 2nd column will be the sum of rows 1 to 3 in the 1st column, etc.

Thanks in advance.

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Use the streamstats command

| streamstats sum(HourlyClients) as CumulativeClients

View solution in original post

Manasa_401
Communicator

you can also use accum command as an alternate to streamstats

|accum HourlyClients as total

If this answer helps, an upvote would be appreciated.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use the streamstats command

| streamstats sum(HourlyClients) as CumulativeClients

mark_groenveld
Path Finder

That works.  Many thanks!

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...