i'm trying to sum one of the fields values based on the other field values.
For example
Source Remediated Space_id
A 45 156
B 46 199
B 98 233
B 8 233
A 9 156
D 3 148
So here i want to sum the Remediated Values with the corresponding space_id values.
if space_id is 233 then want to add 98+8.
Result should be like.
Source Remediated Space_id
A 54 156
B 46 199
B 106 233
D 3 148
is this possible .
Please help me.
Hi @kirrusk ,
try something like this:
your_search
| stats sum(Remediated) AS Remediated BY Source Space_id
| table Source Remediated Space_id
Ciao.
Giuseppe
Can you please try this?
YOUR_SEARCH | stats sum(Remediated) as Remediated by Source,Space_id
Sample Search:
| makeresults | eval _raw="Source Remediated Space_id
A 45 156
B 46 199
B 98 233
B 8 233
A 9 156
D 3 148" | multikv forceheader=1 | stats sum(Remediated) as Remediated by Source,Space_id
your_search
| stats sum(Remediated) AS Remediated BY Source Space_id
| table Source Remediated Space_id
Hi @kirrusk ,
try something like this:
your_search
| stats sum(Remediated) AS Remediated BY Source Space_id
| table Source Remediated Space_id
Ciao.
Giuseppe