Splunk Search
Highlighted

How do I append a column to a chart?

Explorer

I have the following search

index=firewall policyname="/Common/default" requeststatus=blocked (violations="Access from malicious IP address" OR violations="Web scraping detected") | chart count over date_mday by violations

which gives the following chart
datemday Access from malicious IP address Web scraping detected
14 18951 65
15 16891 176
but what I want is
date
mday Access from malicious IP address Web scraping detected Total
14 18951 65 19016
15 16891 176 17067

0 Karma
Highlighted

Re: How do I append a column to a chart?

I think this should do it:
| addtotals "Access from malicious IP address" "Web scraping detected" fieldname=Total

View solution in original post

0 Karma
Highlighted

Re: How do I append a column to a chart?

Explorer

This worked exactly the way I needed. Thank you!

0 Karma