Hi folks, newbie here, trying to use Splunk to do some stuff...
I have a search that ends like below:
| table DaysSinceLastAccess Good IdealbutUnlikely NotGood Actual
| sort by num(DaysSinceLastAccess)
| streamstats sum(Actual) as ActualCumulative
So has the stats as:
I would like to calculate the total on column Actual, via addcoltotals? then divide each row by this total.
How can I achieve this?
Append below to your search
| eventstats sum(Actual) as Total | eval yourNewField = ActualCumulative/Total
View solution in original post
thanks! exactly what i wanted.