Splunk Search

How to run two function in single query?

geetanjali
Path Finder

hi,

I want to display sum of latest values in "SingleValue" module. what would be my query?
i am using :-

<module name="HiddenSearch" layoutPanel="panel_row2_col1" autoRun="True">
    <param name="search">index="test" sourcetype="power_usage" | chart sum(Power_consumption) as Total(W)  </param>
          <module name="SingleValue">
            <param name="beforeLabel">現在の消費電力: </param>
            <param name="format">results</param>
            <param name="afterLabel">(W)</param>
          </module>
    </module> 

This module will return over all sum of power consumption. I want to sum only latest values.

like : sum(first(Power_consumption))

How could i update my query?

Please help.

thanks in advance

Tags (1)
0 Karma

hjwang
Contributor

The last function just only return last seen value of your specified field. Or you wanna sum(Power_consumption) during the specified time period, if so, you can add earliest=-1h latest=now in your search string.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...