Splunk Search

Sum of two fields

tej8
New Member

I have two fields "body.response.successfulItemsCount" & "body.successfulItemsCount". I need sum of total of these two fields.

I ran separate queries like this : 1. index= AND | chart sum("body.response.successfulItemsCount") as sum
2. index= AND ** | chart sum("body.successfulItemsCount") as sum

I got accurate result when i run these queries , but how to get total sum of results in one query? I tried this one but not working
index= AND | chart sum("body.response.successfulItemsCount" OR "body.successfulItemsCount") as sum

Tags (1)
0 Karma

whrg
Motivator

Hello @tej8,

Try something like this:

your base search
| stats sum("body.response.successfulItemsCount") AS sum1 sum("body.successfulItemsCount") AS sum2
| eval totalsum = sum1 + sum2
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...