Splunk Search

How to use eval to group dates?

viandyg
Engager

I have 4 columns of data:

Country    City    Date    Price

I want to make a table where the Price column is is summed for each day for a particular City

Example raw data:

Country    City    Date    Price
a1          b1      2019-01-01    5
a1          b2      2019-01-01    3
a2          c1      2019-01-02    4
a2          c1      2019-01-02    7
a2          c2      2019-01-02    2

Desired Output (only the Price in city c1 is summed because it has 2 entries on the same date):

Country    City    Date    Price
a1          b1      2019-01-01    5
a1          b2      2019-01-01    3
a2          c1      2019-01-02    11
a2          c2      2019-01-02    2

I have tried using eventstats sum(Price) as newPrice by Date but it gives weird number for the new column.

I would appreciate any and all help! Please and thank you!

Tags (1)
0 Karma
1 Solution

nareshinsvu
Builder
| stats values(Country) as Country   sum(Price) as Price  by Date  City

View solution in original post

nareshinsvu
Builder
| stats values(Country) as Country   sum(Price) as Price  by Date  City
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

It’s go time — Boston, here we come!

Are you ready to take your Splunk skills to the next level? Get set, because Splunk University is back, and ...