I have a two fields Calendar_week, Count...
I am trying to create a New field as Cumulative count which will add the previous cumulative count with Current Count.
For eg
Calender_week----Count----Cumulative_Count
1 ---- 0 ----0
2 ---- 1 ----1
3 ---- 2 ----3
Is there a search which could do this..
Thanks
Hi @priyaramki16 ,
Take a look at streamstats:
https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Streamstats
In your case, something like the following should do the trick:
your query here
| sort limit=0 "Calendar Week"
| streamstats sum(count) as Cumulative_Count
Hope that helps
Hi @priyaramki16 ,
Take a look at streamstats:
https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Streamstats
In your case, something like the following should do the trick:
your query here
| sort limit=0 "Calendar Week"
| streamstats sum(count) as Cumulative_Count
Hope that helps
Hi @javiergn ...the query you suggested produced a field which is same as count but with first row not filled...
the addition did not happen
Hi @priyaramki16 ,
I made a typo on my answer as I didn't have a lab to check my syntax. See the answer above again.
By the way, make sure your sort is working fine as there seems to be a trailing space in your query between "Calendar" and "Week"
Thanks!! It worked!!