Splunk Search
Highlighted

How to get sum of all columns into a new column?

Explorer

Hi

I need to do a sum of all columns into new column

EVNT  COL1  COL2  COL3 SUM
1       22   22     22  66
2       1     0     0    1

-paull

0 Karma
Highlighted

Re: How to get sum of all columns into a new column?

Champion

Hi

You can try

| makeresults 
| eval EVNT=1,COL1=22,COL2=22,COL3=22,SUM=0 
| foreach COL* 
    [ eval SUM = SUM+<<FIELD>>] 
| table EVNT,COL1,COL2,COL3,SUM

View solution in original post

Highlighted

Re: How to get sum of all columns into a new column?

Explorer

Thanks...

0 Karma
Highlighted

Re: How to get sum of all columns into a new column?

SplunkTrust
SplunkTrust

@paullt12345 ,

Just add |addtotals fieldname=sum to your search and you get a new sum field

https://docs.splunk.com/Documentation/SplunkCloud/7.2.4/SearchReference/Addtotals

Highlighted

Re: How to get sum of all columns into a new column?

Explorer

Thanks it also works as expected.

0 Karma