Splunk Search

How to Combine similar fields?

din98
Explorer

Hey all,

I have a summary table that shows these values and there are also some common values.

 

 

Process Error  Success Total
A 5 5 10
B 6 9 15
A 7 2 9
C 3 8 11
C 1 3 4
B 5 5 10




I want to combine these common values (under Process) and also add the numerical values together. I am hoping for a result like this in my summary table.

Process Error  Success Total
A 12 7 19
B 11 14 25
C 4 11 15

 

Any help would be much appreciated. Thanks!

 

Labels (6)
Tags (2)
0 Karma
1 Solution

danielcj
Communicator

Hello @din98 ,

Please try the following (assuming that your results are already on a table):

 

| stats sum(Error) as Error, sum(Success) as Success by Process
| addtotals

View solution in original post

din98
Explorer

Thanks guys! I generated the results successfully 🙂

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats sum(*) as * by Process

danielcj
Communicator

Hello @din98 ,

Please try the following (assuming that your results are already on a table):

 

| stats sum(Error) as Error, sum(Success) as Success by Process
| addtotals
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...