Splunk Search

How to use eval to group dates?

viandyg
Engager

I have 4 columns of data:

Country    City    Date    Price

I want to make a table where the Price column is is summed for each day for a particular City

Example raw data:

Country    City    Date    Price
a1          b1      2019-01-01    5
a1          b2      2019-01-01    3
a2          c1      2019-01-02    4
a2          c1      2019-01-02    7
a2          c2      2019-01-02    2

Desired Output (only the Price in city c1 is summed because it has 2 entries on the same date):

Country    City    Date    Price
a1          b1      2019-01-01    5
a1          b2      2019-01-01    3
a2          c1      2019-01-02    11
a2          c2      2019-01-02    2

I have tried using eventstats sum(Price) as newPrice by Date but it gives weird number for the new column.

I would appreciate any and all help! Please and thank you!

Tags (1)
0 Karma
1 Solution

nareshinsvu
Builder
| stats values(Country) as Country   sum(Price) as Price  by Date  City

View solution in original post

nareshinsvu
Builder
| stats values(Country) as Country   sum(Price) as Price  by Date  City
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...