Splunk Search
Highlighted

How to sum top30 and then sum top31-100 and then sum top101-500

Explorer

I have use sort event from big to small ,now i want to sum 1-30,31-100,101-500,501-3000,3000- .how to do it ? thanks in advance.

Tags (3)
0 Karma
Highlighted

Re: How to sum top30 and then sum top31-100 and then sum top101-500

Contributor

Something like this should do it:

* | top limit=100 foo | eval a=1 | accum a | rangemap field=a 1-30=1-30 31-100=31-100 101-500=101-500 501-3000=501-3000 default=large | stats sum(count) by range
Highlighted

Re: How to sum top30 and then sum top31-100 and then sum top101-500

Explorer

Thanks ,vbumgarner!

0 Karma