Splunk Search

Trying to map total throughout the day

aldrichb
Explorer

I have a search that gives me the total license usage in gb's for a given time:

 

index=_internal source=*license_usage.log type=Usage pool=* | stats sum(b) as bu | eval gbu=round(bu/1024/1024/1024,3) | fields gbu

 

I'd like to have a timechart/graph to show what the total is each hour of a given day. Is this possible to do with this timechart?

 

Labels (3)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

So you want your usage to show a cumulative value rather than the value for the specific hour?  If so, just add this to the end

| streamstats sum(gbu) as gbu

which will accumulate the hourly values and replace the hourly values with cumulative total.

If you want both values, then add this to the end instead of the above

| streamstats sum(gbu) as cum_gbu

 this will create a new field with the cumulative total

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Sure you can, just use timechart, like this

index=_internal source=*license_usage.log type=Usage pool=* 
| timechart span=1h sum(b) as gbu 
| eval gbu=round(gbu/1024/1024/1024,3)

aldrichb
Explorer

Thanks for this. The results of this don't seem to "Add up" every hour. I was hoping each hour the number would be greater, but it seems to be giving different numbers, if that makes sense.

0 Karma

bowesmana
SplunkTrust
SplunkTrust

So you want your usage to show a cumulative value rather than the value for the specific hour?  If so, just add this to the end

| streamstats sum(gbu) as gbu

which will accumulate the hourly values and replace the hourly values with cumulative total.

If you want both values, then add this to the end instead of the above

| streamstats sum(gbu) as cum_gbu

 this will create a new field with the cumulative total

bowesmana
SplunkTrust
SplunkTrust

Note that with Splunk, there are often more ways to achieve the same goal. For example, you could use this instead of streamstats

| accum gbu

or

| accum gbu as cum_gbu

In the long run, streamstats is a more useful command (and takes more time to get your head around), as it supports split by clauses, whereas accum does not, so tends to be more useful.

 

0 Karma

aldrichb
Explorer

Exactly what I was looking for. I haven't come across the streamstats term yet so this is great. Thank you!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...