Splunk Search

How to run two function in single query?

geetanjali
Path Finder

hi,

I want to display sum of latest values in "SingleValue" module. what would be my query?
i am using :-

<module name="HiddenSearch" layoutPanel="panel_row2_col1" autoRun="True">
    <param name="search">index="test" sourcetype="power_usage" | chart sum(Power_consumption) as Total(W)  </param>
          <module name="SingleValue">
            <param name="beforeLabel">現在の消費電力: </param>
            <param name="format">results</param>
            <param name="afterLabel">(W)</param>
          </module>
    </module> 

This module will return over all sum of power consumption. I want to sum only latest values.

like : sum(first(Power_consumption))

How could i update my query?

Please help.

thanks in advance

Tags (1)
0 Karma

hjwang
Contributor

The last function just only return last seen value of your specified field. Or you wanna sum(Power_consumption) during the specified time period, if so, you can add earliest=-1h latest=now in your search string.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...