Splunk Search

Sum of a multivalue field inside a row

varunCarbyne
Explorer

Sum of a multivalue field inside a row

Hi below is how my processed data look like
alt text

And the expected output is to have aggregated values of Field A, field B, field C and Total,
the expected output looks like below :
alt text

0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@varunCarbyne

Try

YOUR_SEARCH | stats sum("field A") as "field A", sum("field B") as "field B",sum("field C") as "field C",sum(Total) as Total, Values(IP) as IP by User | table User IP "field A" "field B" "field C" Total

View solution in original post

kamlesh_vaghela
SplunkTrust
SplunkTrust

@varunCarbyne

Try

YOUR_SEARCH | stats sum("field A") as "field A", sum("field B") as "field B",sum("field C") as "field C",sum(Total) as Total, Values(IP) as IP by User | table User IP "field A" "field B" "field C" Total

DalJeanis
Legend

Come on, @kamlesh_vaghela , if you're going to answer correctly, make it an answer!

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Thanks, @DalJeanis 🙂

Converted to Answer.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi varunCarbyne,
could you share your search?
Bye.
Giuseppe

0 Karma

varunCarbyne
Explorer

I have tried eventstats(FieldA) by User, But its now working

0 Karma

varunCarbyne
Explorer

@vnravikumar @harishalipaka

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...