Splunk Search
Highlighted

How to sum a field with a 'by' clause in pivot UI?

Contributor

index=internal persourcetype_thruput series!=splunkd | eval gb=kb/1024/1024 | timechart span=1d useother=f sum(gb) by series

So I have a created a root datamodel of index=_internal source=/opt/splunk/var/log/splunk/metrics.log*

and a child object of persourcetypethruput series!=splunkd

and an eval field for gb that is kb/1024/1024

I'm getting the right fields, but for the field gb field I have no sum function with or without putting a by clause split. What do I have to do to sum a field with a by clause in pivot UI?

Tags (4)
0 Karma
Highlighted

Re: How to sum a field with a 'by' clause in pivot UI?

SplunkTrust
SplunkTrust

Make sure you set the type of that field to Number rather than String.

0 Karma