Splunk Search

How do I append a column to a chart?

j_partsch
Explorer

I have the following search

index=firewall policy_name="/Common/default" request_status=blocked (violations="Access from malicious IP address" OR violations="Web scraping detected") | chart count over date_mday by violations

which gives the following chart
date_mday Access from malicious IP address Web scraping detected
14 18951 65
15 16891 176
but what I want is
date_mday Access from malicious IP address Web scraping detected Total
14 18951 65 19016
15 16891 176 17067

0 Karma
1 Solution

elliotproebstel
Champion

I think this should do it:
| addtotals "Access from malicious IP address" "Web scraping detected" fieldname=Total

View solution in original post

0 Karma

elliotproebstel
Champion

I think this should do it:
| addtotals "Access from malicious IP address" "Web scraping detected" fieldname=Total

0 Karma

j_partsch
Explorer

This worked exactly the way I needed. Thank you!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...