Splunk Search

Total of 2 rows

g_paternicola
Path Finder

Hi everyone, I have a table which gives me 2 fields Username and Duration. How can I dedup the Username and add the total of the Duration in one row?

g_paternicola_0-1622551839751.png

Thank you very much!

Labels (2)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@g_paternicola 

Can you please try this?

YOUR_SEARCH
| rex field="Duration" "(?<hours>\d+)h:(?<minutes>\d+)m:(?<seconds>\d+)s" 
| eval Duration = ((hours*60*60)+(minutes*60)+(seconds))
| stats sum(Duration) as Duration by Username
| eval Duration=tostring(Duration,"duration")

 

My Sample Search :

| makeresults 
| eval Username="A", Duration="0h:40m:42s" 
| append 
    [| makeresults 
    | eval Username="A", Duration="1h:40m:42s"] 
| rex field="Duration" "(?<hours>\d+)h:(?<minutes>\d+)m:(?<seconds>\d+)s" 
| eval Duration = ((hours*60*60)+(minutes*60)+(seconds))
| stats sum(Duration) as Duration by Username
| eval Duration=tostring(Duration,"duration")


 Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The stats command will do that.

... | stats sum(Duration) as Duration by Username

For it to work well, however, the Duration field must be a number rather than a string.

---
If this reply helps you, Karma would be appreciated.
0 Karma

g_paternicola
Path Finder

yeah, I also believe that, because I didn't get any results on the Duration

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...