Splunk Search

stats sum?

efelder0
Communicator

From my list of field in Splunk, I have three fields with numeric values that I would like to add together and assign the total to a field called "Total_Threat_Count".

i.e. - Critical_Severity = 50 + Medium_Severity = 25 + Low_Severity = 25 AS Total_Threat_Count (100)

What would the stats command that would work best here.

I have tried stats sum(Critical_Severity, Medium_Severity, Low_Severity) AS Total_Threat_Count, but I am getting a blank value for that field.

Tags (1)
0 Karma

cphair
Builder

I think you want to use eval here. Something like

... | eval Total_Threat_Count=Critical_Severity + Medium_Severity + Low_Severity | table host, Total_Threat_Count

should work.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...