Splunk Search

Total of 2 rows

g_paternicola
Path Finder

Hi everyone, I have a table which gives me 2 fields Username and Duration. How can I dedup the Username and add the total of the Duration in one row?

g_paternicola_0-1622551839751.png

Thank you very much!

Labels (2)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@g_paternicola 

Can you please try this?

YOUR_SEARCH
| rex field="Duration" "(?<hours>\d+)h:(?<minutes>\d+)m:(?<seconds>\d+)s" 
| eval Duration = ((hours*60*60)+(minutes*60)+(seconds))
| stats sum(Duration) as Duration by Username
| eval Duration=tostring(Duration,"duration")

 

My Sample Search :

| makeresults 
| eval Username="A", Duration="0h:40m:42s" 
| append 
    [| makeresults 
    | eval Username="A", Duration="1h:40m:42s"] 
| rex field="Duration" "(?<hours>\d+)h:(?<minutes>\d+)m:(?<seconds>\d+)s" 
| eval Duration = ((hours*60*60)+(minutes*60)+(seconds))
| stats sum(Duration) as Duration by Username
| eval Duration=tostring(Duration,"duration")


 Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The stats command will do that.

... | stats sum(Duration) as Duration by Username

For it to work well, however, the Duration field must be a number rather than a string.

---
If this reply helps you, Karma would be appreciated.
0 Karma

g_paternicola
Path Finder

yeah, I also believe that, because I didn't get any results on the Duration

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...