Splunk Search

Why does addcoltotals not display decimal totals?

andrewtrobec
Builder

Hello,
I've noticed that the addcoltotals command doesn't display decimals if the total contains a decimal. Run anywhere code:

| makeresults
| eval decimal = 1.5
| eval whole = 1.5
| append [ | makeresults
| eval decimal = 1
| eval whole = 1.5]
| addcoltotals

I'm using Splunk 6.4.1 and my results are:

decimal,whole
1.5,1.5
1,1.5
2,3.0 (here it truncates to a single decimal place for the decimal field)

Is there something I'm missing?
Regards,
Andrew

0 Karma
1 Solution

harishalipaka
Builder

hi @andrewtrobec

try like this

| makeresults
 | eval decimal = 1.5
 | eval whole = 1.5
 | append [ | makeresults
 | eval decimal = 1
 | eval whole = 1.5]
 |eval decimal=round(decimal,2)  |eval whole=round(whole,2) |addcoltotals

View solution in original post

harishalipaka
Builder

hi @andrewtrobec

try like this

| makeresults
 | eval decimal = 1.5
 | eval whole = 1.5
 | append [ | makeresults
 | eval decimal = 1
 | eval whole = 1.5]
 |eval decimal=round(decimal,2)  |eval whole=round(whole,2) |addcoltotals

View solution in original post

harishalipaka
Builder

Hi @andrewtrobec
Did you get that.
If my answer helped you please accept answer or up vote

0 Karma

andrewtrobec
Builder

This is a good workaround, thank you!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It looks like addcoltotals is using the lowest level of precision of the values it's adding. Since '1' has zero digits of precision, that's what is used for the result.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!