Splunk Search

Show subtotals in results table

MatMeredith
Path Finder

I have a search returning results in a table with columns for:
date, username, eventcount

I'd like to display subtotals in the table something like this.

  • Monday, Fred, 7
  • Monday, Joe, 15
  • Totals for Monday 22
  • Tuesday, Fred 10
  • Totals for Tuesday 10
  • etc

Is it possible?

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Appendpipe might hold the answers for you;

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Appendpipe

your base search | stats count by date username | appendpipe [stats sum(count) as count by date | eval username = "Total"]

Hope this helps,

Kristian

View solution in original post

kristian_kolb
Ultra Champion

Appendpipe might hold the answers for you;

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Appendpipe

your base search | stats count by date username | appendpipe [stats sum(count) as count by date | eval username = "Total"]

Hope this helps,

Kristian

kristian_kolb
Ultra Champion

eval username = "Totals for " ?

0 Karma

MatMeredith
Path Finder

Thanks -- that looks like it'll do the job. Now I just need to figure whether I can get those total rows formatted differently (like shown in bold)...

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...