Splunk Search

How to create A new field which creates accumulative results from current and previous records of different field

priyaramki16
Path Finder

I have a two fields Calendar_week, Count...

I am trying to create a New field as Cumulative count which will add the previous cumulative count with Current Count.

For eg 

Calender_week----Count----Cumulative_Count

1                              ---- 0        ----0

2                              ---- 1       ----1

3                             ---- 2       ----3

 

Is there a search which could do this..

Thanks

Labels (2)
0 Karma
1 Solution

javiergn
Super Champion

Hi @priyaramki16 ,

 

Take a look at streamstats: 

https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Streamstats

In your case, something like the following should do the trick:

 

your query here
| sort limit=0 "Calendar Week"
| streamstats sum(count) as Cumulative_Count

 

 

 

Hope that helps

View solution in original post

javiergn
Super Champion

Hi @priyaramki16 ,

 

Take a look at streamstats: 

https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Streamstats

In your case, something like the following should do the trick:

 

your query here
| sort limit=0 "Calendar Week"
| streamstats sum(count) as Cumulative_Count

 

 

 

Hope that helps

priyaramki16
Path Finder

Hi @javiergn ...the query you suggested produced a field which is same as count but with first row not filled...

the addition did not happen

priyaramki16_0-1592303324342.png

 

0 Karma

javiergn
Super Champion

Hi @priyaramki16 ,

 

I made a typo on my answer as I didn't have a lab to check my syntax. See the answer above again.

By the way, make sure your sort is working fine as there seems to be a trailing space in your query between "Calendar" and "Week"

0 Karma

priyaramki16
Path Finder

Thanks!! It worked!!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...