Splunk Search

How to calculate row sum which each column has different weight?

hakusama1024
New Member

Hi

I have a table as below.

severity S0 S1 S2 S3
event A 1 0 0 0
event B 0 2 0 0
event C 0 1 1 0

each column has different weight. for example S0 = 1,000,000, S1 = 10,000, S2 = 100, S3 = 1. i want to sort the event based on the weight multiply by the event number.
Please advise.

Tags (3)
0 Karma
1 Solution

HeinzWaescher
Motivator

try this:

| eval weight=(S0*1000000 + S1*10000 + S2*100 + S3*1)
| sort 0 - weight

View solution in original post

HeinzWaescher
Motivator

try this:

| eval weight=(S0*1000000 + S1*10000 + S2*100 + S3*1)
| sort 0 - weight

hakusama1024
New Member

thank you sir.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...