Right now I have a search which outputs the following:
Gateway Hub Interface MaxSpeed CurrentBPS
router1.boston Boston so-0/0/0.0 10000000000 3843026418
router2.boston Boston so-0/0/1.0 10000000000 3813472541
What I'm trying to do is sum up this data by Hub so that it looks like:
Hub MaxSpeed CurrentBPS
Boston 20000000000 7656498959
The end result being a culmination of data per Hub. I tried using bucket and transaction, but just couldn't get it to work right. Maybe eval will work, but I wasn't skilled enough to get that working either. Any suggestions are greatly appreciated.
Thanks,
Something like this?
<search> | stats latest(bps_out) AS CurrentBPS BY Gateway,Hub,Interface,MaxSpeed | stats sum(MaxSpeed) sum(CurrentBPS) by Hub
Something like this?
<search> | stats latest(bps_out) AS CurrentBPS BY Gateway,Hub,Interface,MaxSpeed | stats sum(MaxSpeed) sum(CurrentBPS) by Hub
It's always the simple things that get you. 🙂
Thanks, that did it.