Splunk Search

How to get the sum of multiple rows based on a different column?

dwear
Explorer

I have a CSV with 3 columns; Username, AD group, Logins (Logins being total number of logins for that user). I want to sum the number of total logins per Active Directory group. I started with:

|stats(count) by group

But that just gives me the number of times each group appears in the CSV (which generally equals the number of users in that group). How do I make it sum Logins per AD Group?

Any help is appreciated.

0 Karma
1 Solution

somesoni2
Revered Legend

Use this. Your question describe the solution

How do I make it sum Logins per AD Group?

your base search | stats sum(Logins) as count by group

View solution in original post

0 Karma

somesoni2
Revered Legend

Use this. Your question describe the solution

How do I make it sum Logins per AD Group?

your base search | stats sum(Logins) as count by group
0 Karma

dwear
Explorer

Thanks. The "as count" is what I was missing I guess.

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...