Splunk Search
Highlighted

Sum of a multivalue field inside a row

Explorer

Sum of a multivalue field inside a row

Hi below is how my processed data look like
alt text

And the expected output is to have aggregated values of Field A, field B, field C and Total,
the expected output looks like below :
alt text

0 Karma
Highlighted

Re: Sum of a multivalue field inside a row

Explorer

I have tried eventstats(FieldA) by User, But its now working

0 Karma
Highlighted

Re: Sum of a multivalue field inside a row

Explorer

@vnravikumar @harishalipaka

0 Karma
Highlighted

Re: Sum of a multivalue field inside a row

Legend

Hi varunCarbyne,
could you share your search?
Bye.
Giuseppe

0 Karma
Highlighted

Re: Sum of a multivalue field inside a row

SplunkTrust
SplunkTrust

@varunCarbyne

Try

YOUR_SEARCH | stats sum("field A") as "field A", sum("field B") as "field B",sum("field C") as "field C",sum(Total) as Total, Values(IP) as IP by User | table User IP "field A" "field B" "field C" Total

View solution in original post

0 Karma
Highlighted

Re: Sum of a multivalue field inside a row

SplunkTrust
SplunkTrust

Come on, @kamlesh_vaghela , if you're going to answer correctly, make it an answer!

0 Karma
Highlighted

Re: Sum of a multivalue field inside a row

SplunkTrust
SplunkTrust

Thanks, @DalJeanis 🙂

Converted to Answer.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.