Splunk Search

How to create a table with max and sum values

HelloItsMe76
Explorer

I have a table like the below

 

Category   | Time |  Count of string

A | t-5mins | 18

A | t-10mins | 7

A | t-15mins | 10

A | t-20 mins | 1

B | t-5mins | 6

B | t-10 mins | 18

 

I would like to create a table with the latest (max) time and the sum of the count by category so that i get this

 

Category   | Max Time |  Sum

A | t-5mins |  36

B | T-5mins | 24

 

I can get the max time and the sum individually into a table but am having issues getting them both into 1 table -  the time and sum values are coming up blank. 

Can someone advise please?

 

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried something like this?

| stats max(time) as maxTime sum(count) as sum by Category
0 Karma

HelloItsMe76
Explorer

Hey, thanks for the response.  yes i have and it returns the correct data for the 2 fields but it doesnt pass in the Category field which i need. How can i get all 3 fields?

0 Karma

HelloItsMe76
Explorer

actually it did work. i had been using 'by Category' on both fields. thanks for the help!

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...