Splunk Search

Total of 2 rows

g_paternicola
Path Finder

Hi everyone, I have a table which gives me 2 fields Username and Duration. How can I dedup the Username and add the total of the Duration in one row?

g_paternicola_0-1622551839751.png

Thank you very much!

Labels (2)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@g_paternicola 

Can you please try this?

YOUR_SEARCH
| rex field="Duration" "(?<hours>\d+)h:(?<minutes>\d+)m:(?<seconds>\d+)s" 
| eval Duration = ((hours*60*60)+(minutes*60)+(seconds))
| stats sum(Duration) as Duration by Username
| eval Duration=tostring(Duration,"duration")

 

My Sample Search :

| makeresults 
| eval Username="A", Duration="0h:40m:42s" 
| append 
    [| makeresults 
    | eval Username="A", Duration="1h:40m:42s"] 
| rex field="Duration" "(?<hours>\d+)h:(?<minutes>\d+)m:(?<seconds>\d+)s" 
| eval Duration = ((hours*60*60)+(minutes*60)+(seconds))
| stats sum(Duration) as Duration by Username
| eval Duration=tostring(Duration,"duration")


 Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The stats command will do that.

... | stats sum(Duration) as Duration by Username

For it to work well, however, the Duration field must be a number rather than a string.

---
If this reply helps you, Karma would be appreciated.
0 Karma

g_paternicola
Path Finder

yeah, I also believe that, because I didn't get any results on the Duration

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...