Are there any new ideas for this problem? How do I get Splunk to write the sum per bar next to it? You can display the single values, the maximum value and the minimum value, but not the total. What is the reason for this?
The easiest way to do this would be to create a dashboard, and have the dashboard delivered on a schedule.
Your dashboard could have two searches, one which is a graphic and the other which shows the table with totals.
For example, search1 could be the stacked bar chart
yoursearchhere
| chart count by errorCode host
and search2 could be the table (even though you use the chart command)
yoursearchhere
| chart count by errorCode host
| addcoltotals
See how to Generate Dashboard PDFs and send via email here.
Yes, I already have a dashboard scheduled. I just want to show the total of each stacked bar, as that is an useful information. I don't want to have another table just for the totals. Please suggest.