How can I create a query where I can sum the total...

Carolina

Engager

02-08-2018
02:42 PM

Hello,

I need your help for the following:

I need to add the Total row and then divide it by the column of funds.

Example total 559892+32398=592190/funds consecutive

and add the percentage in another column that is called% of total

My Query is the following

```
search........
| rex field=Cuenta (?<BIN6>\d{6})
| lookup Bines_Lookup BIN as BIN6 OUTPUT DES as Descripcion_BIN TTARGETA as TTARGETA
| search Descripcion_BIN!="N/A"
| bucket _time span=2h
| chart limit=0 count by BIN6 Respuesta
| addtotals fieldname=Approved Approved* Honor* Partially*
| addtotals fieldname=Rejected Refer* Allowable* Do* Error* Collect* No* Customer* Retry* Transaction* Bank* Partially* Expired* Suspicion* Call* Restricted* all* Lost* Stolen* Not* Incorrect* Exceeds* Hard* Response* Issuer* Financial* Duplicate* PTLF* Bad* Pick* Invalid* Requirement* Suspicious* File* Format* It* Reserved*
| table BIN6 Approved Rejected Others "Not sufficient funds"
| eval "% Aceptation" = round(Approved/(Approved+Rejected)*100, 2)
| rename "Not sufficient funds" as fondos
| table BIN6 Approved Rejected "% Aceptation" fondos
| addcoltotals label=Total Approved Rejected labelfield=BIN6
| addtotals fieldname=total1 Total*
| eval "% of total"=(Total/fondos)*10
| table BIN6 Approved Rejected "% Aceptation" fondos "% of total"
```

Re: How can I create a query where I can sum the total and then take the percentage and add them in a column?

493669

Super Champion

02-08-2018
05:37 PM

row of funds =5000 how you have get this?

Re: How can I create a query where I can sum the total and then take the percentage and add them in a column?

Carolina

Engager

02-08-2018
05:52 PM

592190/2, 592190/47

to have a new column

Re: How can I create a query where I can sum the total and then take the percentage and add them in a column?

p_gurav

Champion

02-08-2018
10:10 PM

Hi,

Are u talking about something similar to this solution provided in this question?

https://answers.splunk.com/answers/488926/how-to-get-a-total-count-and-count-by-specific-fie-1.html

Re: How can I create a query where I can sum the total and then take the percentage and add them in a column?

Carolina

Engager

03-14-2018
09:03 AM

thank you !

Re: How can I create a query where I can sum the total and then take the percentage and add them in a column?

493669

Super Champion

02-08-2018
10:59 PM

Try this:

```
...|appendpipe[|search BIN6=total|eval Sum=Approved + Rejected ]|eventstats sum(Sum) as summation|eval "% of total" =summation*100/test."%"
```

let me know if it helps!

KailA

Contributor

02-09-2018
02:06 AM

Hi,

Start by removing this :

```
| addcoltotals label=Total Approved Rejected labelfield=BIN6
| addtotals fieldname=total1 Total*
| eval "% of total"=(Total/fondos)*10
| table BIN6 Approved Rejected "% Aceptation" fondos "% of total"
```

And replace it by this :

```
| eventstats sum(Approved) as tot_aproved sum(Rejected) as tot_rejected
| eval Total = tot_approved + tot_rejected
| eval "% of total" = (Total / fondos) * 10
| table ...
```

This sould work well !

Re: How can I create a query where I can sum the total and then take the percentage and add them in a column?

Carolina

Engager

02-11-2018
09:07 AM

Thank you for help. I worked the solution