I'm trying to add a column to the right of OTHER, which sums up the entire row counts of each errorType per day. So for example, the first value in a column farthest to the right would be the total count for api_error + approved + declined + expired_Card etc. for each day.
My current search is gateway=firstdata errorType!=null event=transactionCompleted | timechart count by errorType span="1m"
Look at the addtotals
command.
My current search is gateway=firstdata errorType!=null event=transactionCompleted | timechart count by errorType span="1m" | addtotals
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Addtotals