Splunk Search

How to create A new field which creates accumulative results from current and previous records of different field

priyaramki16
Path Finder

I have a two fields Calendar_week, Count...

I am trying to create a New field as Cumulative count which will add the previous cumulative count with Current Count.

For eg 

Calender_week----Count----Cumulative_Count

1                              ---- 0        ----0

2                              ---- 1       ----1

3                             ---- 2       ----3

 

Is there a search which could do this..

Thanks

Labels (2)
0 Karma
1 Solution

javiergn
Super Champion

Hi @priyaramki16 ,

 

Take a look at streamstats: 

https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Streamstats

In your case, something like the following should do the trick:

 

your query here
| sort limit=0 "Calendar Week"
| streamstats sum(count) as Cumulative_Count

 

 

 

Hope that helps

View solution in original post

javiergn
Super Champion

Hi @priyaramki16 ,

 

Take a look at streamstats: 

https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Streamstats

In your case, something like the following should do the trick:

 

your query here
| sort limit=0 "Calendar Week"
| streamstats sum(count) as Cumulative_Count

 

 

 

Hope that helps

priyaramki16
Path Finder

Hi @javiergn ...the query you suggested produced a field which is same as count but with first row not filled...

the addition did not happen

priyaramki16_0-1592303324342.png

 

0 Karma

javiergn
Super Champion

Hi @priyaramki16 ,

 

I made a typo on my answer as I didn't have a lab to check my syntax. See the answer above again.

By the way, make sure your sort is working fine as there seems to be a trailing space in your query between "Calendar" and "Week"

0 Karma

priyaramki16
Path Finder

Thanks!! It worked!!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...