Splunk Search

## Sum or count by same value

Path Finder

We are trying to sum two values based in the same common key between those two rows and for the ones missing a value should be considered as a cero, to be able to sum both fields (eval Count=Job_Count + Request_Count) .

Expected result should be:
006341102527 5
011561102529 5
011971102529 6
012381102528 5

Tags (4)
1 Solution
SplunkTrust

Hi rsokolova,
If you always have only one between Job_Count and Request_Count, you can try something like this:

``````your_search
| eval Count=coalesce(Job_Count,Request_Count)
| stats sum(Count) AS Count BY PO_Ready
``````

otherwise if you have for a PO_Ready both Job_Count and Request_Count, you can try something like this:

``````your_search
| stats sum(Job_Count) AS Job_Count sum(Request_Count) As Request_Count BY PO_Ready
| eval Count=Job_Count + Request_Count
``````

Bye.
Giuseppe

SplunkTrust

Hi rsokolova,
If you always have only one between Job_Count and Request_Count, you can try something like this:

``````your_search
| eval Count=coalesce(Job_Count,Request_Count)
| stats sum(Count) AS Count BY PO_Ready
``````

otherwise if you have for a PO_Ready both Job_Count and Request_Count, you can try something like this:

``````your_search
| stats sum(Job_Count) AS Job_Count sum(Request_Count) As Request_Count BY PO_Ready
| eval Count=Job_Count + Request_Count
``````

Bye.
Giuseppe

Path Finder

Thanks cusello for the quick reply the coalesce command did the trick.

Take the 2021 Splunk Career Survey

### Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey.Earn \$50 in Amazon cash! Full Details! >

Get Updates on the Splunk Community!