Splunk Search

how to get the aggregation count of field values?

vrmandadi
Builder

I am looking something like the following result

  • A_Count AGGREGATE TOTAL 20 20 30 50 10 60

I know delta command will give the difference but is there any command which gives the aggregation

0 Karma

vrmandadi
Builder
0 Karma

skoelpin
SplunkTrust
SplunkTrust

You should check out addcoltotals

It will work like this | addcoltotals labelfield=change_name label=ALL

http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Addcoltotals

0 Karma

vrmandadi
Builder

I know about addcoltotals,but that does not do something like a delta where For each event where field is a number, the delta command computes the difference, in search order, between the field value for the event and the field value for the previous event. The delta command writes this difference into newfield.

In the similar manner instead of difference I am looking for addition of it

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...