Splunk Search

how to sum everyday result

ypfbkg
Explorer

this is my search srcipt, it will show everyday use some apps count

sourcetype="acclog" app="molly" OR app="wms" |timechart span="1d" dc(IP) as visitor by app |sort visitor

the result like

_time   Molly   wms

12-7-10 22 265

12-7-11 3 22

how can i sum the total count, like below

app counter

Molly 25

wms 287

Could someone can help me ? Thanks.

Tags (2)
0 Karma
1 Solution

kallu
Communicator

Ah ... missed your point completely. In that case you can use eval to create a new field with IP and date combined.

... | eval X=IP.date_year.date_month.date_mday | stats dc(X) as visitor by app | ...

View solution in original post

0 Karma

kallu
Communicator

Ah ... missed your point completely. In that case you can use eval to create a new field with IP and date combined.

... | eval X=IP.date_year.date_month.date_mday | stats dc(X) as visitor by app | ...

0 Karma

ypfbkg
Explorer

Kallu, thanks your help.

yes, this is what i want ^___^

0 Karma

kallu
Communicator


... | stats dc(IP) as visitor by app | sort visitor

0 Karma

ypfbkg
Explorer

i try this , but it didn't count erveyday. if some IP is in
2 day, it's counter will be "1", but i want 2

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...