Splunk Search

how to sum everyday result

ypfbkg
Explorer

this is my search srcipt, it will show everyday use some apps count

sourcetype="acclog" app="molly" OR app="wms" |timechart span="1d" dc(IP) as visitor by app |sort visitor

the result like

_time   Molly   wms

12-7-10 22 265

12-7-11 3 22

how can i sum the total count, like below

app counter

Molly 25

wms 287

Could someone can help me ? Thanks.

Tags (2)
0 Karma
1 Solution

kallu
Communicator

Ah ... missed your point completely. In that case you can use eval to create a new field with IP and date combined.

... | eval X=IP.date_year.date_month.date_mday | stats dc(X) as visitor by app | ...

View solution in original post

0 Karma

kallu
Communicator

Ah ... missed your point completely. In that case you can use eval to create a new field with IP and date combined.

... | eval X=IP.date_year.date_month.date_mday | stats dc(X) as visitor by app | ...

0 Karma

ypfbkg
Explorer

Kallu, thanks your help.

yes, this is what i want ^___^

0 Karma

kallu
Communicator


... | stats dc(IP) as visitor by app | sort visitor

0 Karma

ypfbkg
Explorer

i try this , but it didn't count erveyday. if some IP is in
2 day, it's counter will be "1", but i want 2

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...