Splunk Search

How to specify which columns are totaled up?

Path Finder

What columns can I somehow override and specify which ones are totaled up? I only want the count to be totaled but other error codes are getting totaled as well.

alt text

Tags (2)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

@jaj refer to addtotals or addcoltotals command which you can apply only for specific column

Forexample:

 | addtotals row=f col=t labelfield="Error Message" Count
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

@jaj refer to addtotals or addcoltotals command which you can apply only for specific column

Forexample:

 | addtotals row=f col=t labelfield="Error Message" Count
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

Path Finder

@niketnilay thank you again!

0 Karma