Splunk Search

incremental value

DataOrg
Builder

I have sequence no of to populate . first column is the sequence of no and answers need to like in the second column

for Example
value value to populate
10 1
10 1
10 1
15 2
15 2
10 3

0 Karma
1 Solution

HiroshiSatoh
Champion

If increment is added for every NO ...

(your search)| streamstats sum(value)  by no

View solution in original post

HiroshiSatoh
Champion

If increment is added for every NO ...

(your search)| streamstats sum(value)  by no

DataOrg
Builder

its not sum.
we need to have a sequence of no if value are same we need to mark it as 1 . if current sequence changes to other set of no. we need to increase the value by 1

0 Karma

HiroshiSatoh
Champion

How's this?

 (your search)
|autoregress p=1 no as no_old
|eval change=if(no=no_old,0,1)
| streamstats sum(change) as inc_value
|table no inc_value
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...