I have a search that extracts the events and fields that I want. I want to sum the fields in like events. Here is a sample of the data that I have:
Events | Field1 | Field2
-------------------------------------
event1 | 6 | 2
event2 | 3 | 1
event1 | 2 | 4
event2 | 1 | 2
event2 | 5 | 2
event3 | 8 | 3
I would like to end up with the following:
Events | Field1 | Field2
-------------------------------------
event1 | 8 | 6
event2 | 9 | 5
event3 | 8 | 3
Is this possible? Any clues?
Try this
<your search> | stats sum(Field1) as Sum1, sum(Field2) as Sum2 by Events | table Events Sum1 Sum2
Try this
<your search> | stats sum(Field1) as Sum1, sum(Field2) as Sum2 by Events | table Events Sum1 Sum2