Splunk Search

How to sum multiple individual columns into a flat row

eric_delac
New Member

I have a search that based on a lookup that is pulling names and totals over the course of a 24 hour period or week based on time. How can I sum each column without having to sum every field individually?

cdr_events duration>0
( (callingPartyGroup="00581" OR originalCalledPartyGroup="00581" OR finalCalledPartyGroup="00581") )

| calculate_all_internal_parties
| lookup groups number as number output name group subgroup
| search ( group="00581" )
| timechart dc(callId) by name

I could get it by running a | sum("Tony Freeman") as "Tony Freeman" sum("Andrea Cook" as "Andrea Cook" etc etc but is there an easier way to do that?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You can use addtotals to sum the column values like this

| addtotals fieldname=sum

https://docs.splunk.com/Documentation/Splunk/8.0.1/SearchReference/Addtotals

0 Karma

eric_delac
New Member

alt text

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...