Splunk Search
Highlighted

How to edit my search to add a column with the total for each list(count) by a field?

Communicator

Hi to everyone

I have this search:

sourcetype="cisco:asa" | stats count by src_ip,dest_ip | sort -count |  stats list(dest_ip),list(count) by src_ip

With this output:

alt text

I need to add a column with the total count by src_ip (sum of all the count for each list(count) value)

Does someone knows how to do this?

regards

0 Karma
Highlighted

Re: How to edit my search to add a column with the total for each list(count) by a field?

SplunkTrust
SplunkTrust

Try something like this

 sourcetype="cisco:asa" | stats count by src_ip,dest_ip | sort -count | eventstats sum(count) as Total by src_ip |  stats list(dest_ip),list(count) values(Total) as Total by src_ip

View solution in original post

Highlighted

Re: How to edit my search to add a column with the total for each list(count) by a field?

Communicator

Very well, it's working, thanks you very much!

0 Karma