how to saving various sums in a variable for future search?
I know it gives you to put a sum on a varivavel, but several I can not
Thanks
Create sums within an event with eval
like this:
... | eval newSum = field1 + field2 ....
Create sums across events with stats
like this:
... | stats sum(field1) sum(field2) ...
Create sums within an event with eval
like this:
... | eval newSum = field1 + field2 ....
Create sums across events with stats
like this:
... | stats sum(field1) sum(field2) ...
... and put those SPL commands into a saved search which does summary indexing http://docs.splunk.com/Documentation/Splunk/6.3.3/Knowledge/Usesummaryindexing and you have it stored for future searches .... if this is what the user wants?
Could you provide more details with examples? What is your current search/output and what do you expect?