Splunk Search

How to sum top30 and then sum top31-100 and then sum top101-500

lihongyan_84
Explorer

I have use sort event from big to small ,now i want to sum 1-30,31-100,101-500,501-3000,3000- .how to do it ? thanks in advance.

Tags (3)
0 Karma

lihongyan_84
Explorer

Thanks ,vbumgarner!

0 Karma

vbumgarner
Contributor

Something like this should do it:

* | top limit=100 foo | eval a=1 | accum a | rangemap field=a 1-30=1-30 31-100=31-100 101-500=101-500 501-3000=501-3000 default=large | stats sum(count) by range
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...