If I have fields that have the potential to contain any number of values, from null to many, how can I get the sum function to work on all cases using stats or chart?
CaseID Process X Time Process Y time Process Z time
When i use "... | stats sum(processx), sum(processy), sum(process z) by caseID
it only sums the cells that have multiple values, not the cells that only contain a single value. Any misconception or misconstruction I'm running into here?
First, your chart is a bit unclear to me - it doesn't look like you have any Process Z values.
In addition, it looks like all events only have one value per field or else they are empty.
Does Splunk even think that these fields are numeric? If you simply run a search, do the fields appear in the fields sidebar at the left - or in the the list if you choose all fields?
I would do some exploration of your field values. There is nothing wrong with your stats command - except for the fact that you wrote process z instead of process_z.