I am looking to sum up cumulative column totals by hour in a separate column.
Here is the search:
index=main CompletedEvent | bin _time span=1h | stats dc(clientid) as HourlyClients by _time
I would like there to be a 2nd result column that accumulates the 1st column by hour. For example: the result in row 2 of the 2nd column will be the sum of rows 1 and 2 in the 1st column, the result of row 3 of the 2nd column will be the sum of rows 1 to 3 in the 1st column, etc.
Thanks in advance.
Use the streamstats command
| streamstats sum(HourlyClients) as CumulativeClients
you can also use accum command as an alternate to streamstats
|accum HourlyClients as total
If this answer helps, an upvote would be appreciated.
Use the streamstats command
| streamstats sum(HourlyClients) as CumulativeClients
That works. Many thanks!