Splunk Search

How to add a field being a sum of previous rows?

tomaszwrona
Explorer

Hello,

i am looking to solve following problem.
How to calculate the fields summary_worked and summary_requested?

month hours_worked summary_worked hours_requested summary_requested
april 160 160 (hours worked for april) 160 160 (hours_requested for april)
may 160 320 (hours worked for april+may) 128 288 (hours_requested for april+may)
june 160 480 (hours worked for april+may+june) 188 476 (hours_requested for april+may+june)

Cheers
Tomasz

Tags (2)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

It sounds like you want a running total. You can do this with the splunk command accum.

You don't give any of your search, so I can only make a complete and total guess as to the search command you'll use, but it could be...

... your base search ... | accum hours_worked AS hours_worked_total | accum hours_requested AS hours_requested_total

Give that a try and see what it gets you. If you need more specific help, but sure to paste in your search and perhaps a few actual events (if the above aren't actual events).

View solution in original post

Richfez
SplunkTrust
SplunkTrust

It sounds like you want a running total. You can do this with the splunk command accum.

You don't give any of your search, so I can only make a complete and total guess as to the search command you'll use, but it could be...

... your base search ... | accum hours_worked AS hours_worked_total | accum hours_requested AS hours_requested_total

Give that a try and see what it gets you. If you need more specific help, but sure to paste in your search and perhaps a few actual events (if the above aren't actual events).

tomaszwrona
Explorer

hi,

this is exactly what i wanted to achieve - thank you!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...