Splunk Search

How to Combine similar fields?

din98
Explorer

Hey all,

I have a summary table that shows these values and there are also some common values.

 

 

Process Error  Success Total
A 5 5 10
B 6 9 15
A 7 2 9
C 3 8 11
C 1 3 4
B 5 5 10




I want to combine these common values (under Process) and also add the numerical values together. I am hoping for a result like this in my summary table.

Process Error  Success Total
A 12 7 19
B 11 14 25
C 4 11 15

 

Any help would be much appreciated. Thanks!

 

Labels (6)
Tags (2)
0 Karma
1 Solution

danielcj
Communicator

Hello @din98 ,

Please try the following (assuming that your results are already on a table):

 

| stats sum(Error) as Error, sum(Success) as Success by Process
| addtotals

View solution in original post

din98
Explorer

Thanks guys! I generated the results successfully 🙂

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats sum(*) as * by Process

danielcj
Communicator

Hello @din98 ,

Please try the following (assuming that your results are already on a table):

 

| stats sum(Error) as Error, sum(Success) as Success by Process
| addtotals
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...