Splunk Search

How to accum a field extra for each user?

p_splunk
Engager

Hi,

i want to accumulate a field per user (and time).

so lets say the users are distinguishable by the field user and the field i want to accumulate per user is XP.

if i do smth like

...| sort 0 +_time | stats c(user) as XPgains by user | accum XP as accumXP

I see in the list of logevents that the function accumulates over all users beginnining from first time event to the very last and the accum fct doesn't take any "by user" or smth like this.

how can I get a field which starts counting new for every user?

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Use streamstats instead:

... | streamstats count by user AS accumXP

View solution in original post

Ayn
Legend

Use streamstats instead:

... | streamstats count by user AS accumXP
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...