Splunk Search

How To Sum Hourly Column Results In A Separate Column

mark_groenveld
Path Finder

I am looking to sum up cumulative column totals by hour in a separate column.

Here is the search:

index=main CompletedEvent | bin _time span=1h | stats dc(clientid) as HourlyClients by _time

I would like there to be a 2nd result column that accumulates the 1st column by hour.  For example:  the result in row 2 of the 2nd column will be the sum of rows 1 and 2 in the 1st column, the result of row 3 of the 2nd column will be the sum of rows 1 to 3 in the 1st column, etc.

Thanks in advance.

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Use the streamstats command

| streamstats sum(HourlyClients) as CumulativeClients

View solution in original post

Manasa_401
Communicator

you can also use accum command as an alternate to streamstats

|accum HourlyClients as total

If this answer helps, an upvote would be appreciated.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use the streamstats command

| streamstats sum(HourlyClients) as CumulativeClients

mark_groenveld
Path Finder

That works.  Many thanks!

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

What’s New in Splunk Enterprise 9.4: Tools for Digital ResilienceTune in to What’s New in Splunk Enterprise ...

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...