Splunk Search

How to add a separate column which displays the total of the count?

pavanae
Builder

The following is my search

…..My Search…… | stats count by orderid,source,host

Which displays the following results

orderid source host count
971729145 /jboss/server/12commerce/log/server.log kvcldprdapp02a 1
106283305 /jboss/server/20cap/log/server.log kvcldprdapp01b 1
147093787 /jboss/server/13commerce/log/server.log kvcldprdapp08b 1
569279529 /jboss/server/11commerce/log/server.log kvcldprdapp01a 2
670563206 /jboss/server/13commerce/log/server.log kvcldprdapp03b 1
862422991 /jboss/server/12commerce/log/server.log kvcldprdapp07b 1
038357748 /jboss/server/12commerce/log/server.log kvcldprdapp03b 1

Now how can i modify my search to display a separate column and shows the total count as follows

orderid source host count Total_Count
971729145 /jboss/server/12commerce/log/server.log kvcldprdapp02a 1 8
106283305 /jboss/server/20cap/log/server.log kvcldprdapp01b 1
147093787 /jboss/server/13commerce/log/server.log kvcldprdapp08b 1
569279529 /jboss/server/11commerce/log/server.log kvcldprdapp01a 2
670563206 /jboss/server/13commerce/log/server.log kvcldprdapp03b 1
862422991 /jboss/server/12commerce/log/server.log kvcldprdapp07b 1
038357748 /jboss/server/12commerce/log/server.log kvcldprdapp03b 1

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

…..My Search…… | stats count by orderid,source,host | eventstats sum(count) as Total_Count

View solution in original post

rroberts
Splunk Employee
Splunk Employee

Have you tried adding ... | appendpipe [stats sum(count) as Total_Count]

somesoni2
Revered Legend

Appendpipe will add a row with total, not the Total as separate column

0 Karma

rroberts
Splunk Employee
Splunk Employee

Yes, but you'll get the total repeated on each row with eventstats. I think he only wants the grand total displayed once?

0 Karma

somesoni2
Revered Legend

Well I may be wrong with interpretation of his requirement. And when I look at the expected output, yes that's misleading.
Guess it upto @pravanae, to decide which format he wanted.

0 Karma

rroberts
Splunk Employee
Splunk Employee

Indeed. I could be wrong too!

0 Karma

somesoni2
Revered Legend

Try this

…..My Search…… | stats count by orderid,source,host | eventstats sum(count) as Total_Count
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...