Splunk Search
Highlighted

how to add a sum in a top search?

Explorer

Hello. I have this search:

*  app="youtube" | top  limit=20 srcip by app showperc=f countfield=total

of this log:

date=2015-01-14 time=08:32:10 srcip=192.168.1.200 app="Youtube" rcvdbyte=121 
date=2015-01-14 time=08:38:10 srcip=192.168.1.200 app="Youtube" rcvdbyte=500
date=2015-01-14 time=08:32:10 srcip=192.168.1.200 app="Youtube" rcvdbyte=900

I need to add the total of bytes received (rcvdbyte) per IP in that App. I tried with stats sum before and after the top but the results are blank. Thanks

Tags (3)
Highlighted

Re: how to add a sum in a top search?

SplunkTrust
SplunkTrust

Give this a try

* app="youtube" | stats sum(rcvdbyte) as rcvdbytes count as total by app,srcip | sort app, -total| streamstats count as sno by app | where sno<21 | table app srcip total rcvdbytes

View solution in original post

Highlighted

Re: how to add a sum in a top search?

Explorer

It didn't work. rcvbytes = null

0 Karma
Highlighted

Re: how to add a sum in a top search?

SplunkTrust
SplunkTrust

Field name was incorrect in my search, updated it now. Check back.

0 Karma
Highlighted

Re: how to add a sum in a top search?

Explorer

Thanks. It works now

0 Karma