Splunk Search

How do you calculate the totals of each table row and display those values as new fields?

johnward4
Communicator

How do you calculate the totals of each single row of a table and display that value in a new fields, much like addcoltotals but for rows?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Use eval.

index=foo | eval total=field1 + field2 + field3 | table field1, field2, field3, total

You can also use foreach if you don't want to add the fields yourself.

index=foo | fields - _time | eval total=0 | foreach * [eval total=total+<<FIELD>>] | table *
---
If this reply helps you, Karma would be appreciated.

View solution in original post

jotne
Builder

You can use the command addtotals totals for rows.

 

| makeresults
| eval mon=10, tue=23, wen=12, thu=2, fri=15
| addtotals

You get a new field with name Total with value 62

 

0 Karma

vikas_baranwal
Path Finder

Hi John,

I hope you must have got the answer but just for addition,

You can also use addtotals in the last of your SPL so it will add a new column named "Total" as last of the columns. and for each row as a result, it will be sum of numeric values of every column in the table.

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use eval.

index=foo | eval total=field1 + field2 + field3 | table field1, field2, field3, total

You can also use foreach if you don't want to add the fields yourself.

index=foo | fields - _time | eval total=0 | foreach * [eval total=total+<<FIELD>>] | table *
---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...