Splunk Search

Why are there sum issues in splunk table?

ositaumeozulu
Explorer

splunk table not giving the accurate sum of the fields in addtotals, even when i use the stats sum function, once the nos exceed 100000, it will not sum itinnacurate result in the addtotalsinnacurate result in the addtotals

Labels (1)
0 Karma

duncangoff3
Splunk Employee
Splunk Employee

it would be a little easier to help if you included the search you used, but from what i can see its because you have a mix of number and text strings. 1234 is a number 1,234 is a string, its adding the numbers and skipping the strings.

to fix you need to either;

 

a. do your sums before adding commas

or 

b. convert you strings to numbers before doing the math
ie | eval numbers=tostring(<string_field>,"commas") | stats sum(numbers)
tonumber(<str>, <base>) .

 

Feel free to reply with your original search if you need any further help.

0 Karma

ositaumeozulu
Explorer

Wow, many thanks @duncangoff3 you are awesome

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...