Splunk Search

How to Combine similar fields?

din98
Explorer

Hey all,

I have a summary table that shows these values and there are also some common values.

 

 

Process Error  Success Total
A 5 5 10
B 6 9 15
A 7 2 9
C 3 8 11
C 1 3 4
B 5 5 10




I want to combine these common values (under Process) and also add the numerical values together. I am hoping for a result like this in my summary table.

Process Error  Success Total
A 12 7 19
B 11 14 25
C 4 11 15

 

Any help would be much appreciated. Thanks!

 

Labels (6)
Tags (2)
0 Karma
1 Solution

danielcj
Communicator

Hello @din98 ,

Please try the following (assuming that your results are already on a table):

 

| stats sum(Error) as Error, sum(Success) as Success by Process
| addtotals

View solution in original post

din98
Explorer

Thanks guys! I generated the results successfully 🙂

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats sum(*) as * by Process

danielcj
Communicator

Hello @din98 ,

Please try the following (assuming that your results are already on a table):

 

| stats sum(Error) as Error, sum(Success) as Success by Process
| addtotals
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...