Splunk Search

cumulative sum in splunk

shreeCS
New Member

Hi,

I have uploaded csv files for indexing and creating reports.Here is the sample entries:

 Date          A  B  
 1.08.2013     8  17
 2.08.2013     9  15
 3.08.2013     11 20
 4.08.2013     8  18

and my expected result is

 Date          A  B   Difference   Cumulative_sum
 1.08.2013     8  17   9                9
 2.08.2013     9  15   6                15
 3.08.2013     11 20   9                24
 4.08.2013     8  18   10               34 

Here i wanted to calculate cumulative sum and show it on a chart.Does splunk provide any direct function to calculate cumulative sum? How to do this?

Thank you

Tags (2)
0 Karma

jonuwz
Influencer

add this :

| streamstats sum(Difference) as Cumulative_sum

shreeCS
New Member

The query is
"sourcetype="csv-5" | convert mstime(Out_Time_hh_mm) AS outtime | convert mstime(In_Time_hh_mm) AS intime |eval durationHrs=(outtime - intime )/60 | streamstats sum(durationHrs) as cumulativeSum by host | timechart values(cumulativeSum) by host "

0 Karma

shreeCS
New Member

i come up with some solution query as given below,but here the problem is cumulative sum is in the reverse order i.e., if i take for August month data,for August 1st its 205 as cumulative sum and for August 31st 8 but this should be in a reverse order i.e ,August 1st 8 ,august2 19...august 31st 205 as a sum

0 Karma

shreeCS
New Member

Here i wanted to show cumulative sum of each host on a chart.How to do that.If i take single host i'm able to do if there are multiple hosts,then how query should be modified?

0 Karma

shreeCS
New Member

yes,the above solution is working fine but if i want to calculate cumulative sum by host ,how to do that?
" |streamstats sum(difference) as cumulative_sum by host" doesn't work here

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...