Splunk Search

How to calculate row sum which each column has different weight?

hakusama1024
New Member

Hi

I have a table as below.

severity S0 S1 S2 S3
event A 1 0 0 0
event B 0 2 0 0
event C 0 1 1 0

each column has different weight. for example S0 = 1,000,000, S1 = 10,000, S2 = 100, S3 = 1. i want to sort the event based on the weight multiply by the event number.
Please advise.

Tags (3)
0 Karma
1 Solution

HeinzWaescher
Motivator

try this:

| eval weight=(S0*1000000 + S1*10000 + S2*100 + S3*1)
| sort 0 - weight

View solution in original post

HeinzWaescher
Motivator

try this:

| eval weight=(S0*1000000 + S1*10000 + S2*100 + S3*1)
| sort 0 - weight

hakusama1024
New Member

thank you sir.

0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...