Hi,
I have a search and an | append [subsearch] which adds at the bottom of the results (see image) a new row with the sum of the values per every column.
Is there a way to assign those results (see 1317 in the image provided) in a constant or a field (through an eval maybe)?
Thanks,
Skender
If you are saying to give the last row a name for the leading field without knowing the name of the field/column, you can do this will fillnull
like this:
... | fillnull value="Total"
Are you looking to add a new field (in your main search result) which will have sum of values of a column (which you're adding through an append subsearch? If yes then try this
your main search | eventstats sum(field1) as TotalField1