Splunk Search

## How to calculate SUM by type?

Path Finder

Hello everyone,

I am trying to SUM the columns.

``````index="nzc-neel-uttar" source="http:kyhkp"
| timechart span=1d count by Type
| eval "New_Date"=strftime(_time,"%Y-%m-%d") ``````
 _time Type-A Type-B New_Date 20/07/2023 3 8 20/07/2023 21/07/2023 4 23 21/07/2023 22/07/2023 66 0 22/07/2023 23/07/2023 90 0 23/07/2023 24/07/2023 0 6 24/07/2023 25/07/2023 0 23 25/07/2023

Desired Output:

 New_Date Type-A Type-B Total 20/07/2023 3 8 11 21/07/2023 4 23 27 22/07/2023 66 0 66 23/07/2023 90 0 90 24/07/2023 0 6 6 25/07/2023 0 23 23

Thanks

Labels (6)

• ### tstats

1 Solution
SplunkTrust
``````index="nzc-neel-uttar" source="http:kyhkp"
| timechart span=1d count by Type
| eval "New_Date"=strftime(_time,"%Y-%m-%d") ``````
SplunkTrust
``````index="nzc-neel-uttar" source="http:kyhkp"
| timechart span=1d count by Type
| eval "New_Date"=strftime(_time,"%Y-%m-%d") ``````
Path Finder

Its working fine, thank you so much!

How to add others columns from the index? Ex: Phase from the same index.

 New_Date Type-A Type-B Total Phase 20/07/2023 3 8 11 1 21/07/2023 4 23 27 1 22/07/2023 66 0 66 1 23/07/2023 90 0 90 1 24/07/2023 0 6 6 1 25/07/2023 0 23 23 abc

Also, remove and rearrange the columns sequence, mentioned in the above table.

SplunkTrust

Unless Phase can be derived from your current results, you could potentially use appendcols, but it depends on your data.

Get Updates on the Splunk Community!

#### Discover SplunkTrust and MVP Articles, Instant Translation, and More on Splunk ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

#### Integrating Kubernetes and Splunk Observability Cloud

We need end-to-end insight into our application environments to confidently ensure everything is up and ...

#### Index This | What has a tail and a head but no body?

July 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...