index=_internal per_sourcetype_thruput series!=splunkd | eval gb=kb/1024/1024 | timechart span=1d useother=f sum(gb) by series
So I have a created a root datamodel of index=_internal source=/opt/splunk/var/log/splunk/metrics.log*
and a child object of per_sourcetype_thruput series!=splunkd
and an eval field for gb that is kb/1024/1024
I'm getting the right fields, but for the field gb field I have no sum function with or without putting a by clause split. What do I have to do to sum a field with a by clause in pivot UI?
Make sure you set the type of that field to Number
rather than String
.