Hi,
I am having a tough time in creating overall sum and aggregate sum. Here is my issue:
I have multiple values between client-server:
source destination client_to_server_bytes server_to_client_bytes
A -- B 10 12
A -- B 10 10
A -- C 50 30
C -- D 15 15
c -- D 10 10
I want to create a table with addition of two values in all occurrences. And final value would have addition of all the additions:
A -- B 42
A -- C 80
C -- D 50
To get first addition I did:
my_search ... | eval total_bytes = exact(val_1 + val_2) | table source destination total_bytes
This correctly gave me following result:
A -- B 22
A -- B 20
...and so on
Now how do I combine them to form a single result?
Like this:
my_search ... | eval total_bytes = exact(val_1 + val_2) | stats sum(total_bytes) by source destination
Like this:
my_search ... | eval total_bytes = exact(val_1 + val_2) | stats sum(total_bytes) by source destination
very true !
It was easy! I am really dumb.. Anyways Thanks for your help !!
So am I but Splunk makes even dummies look brilliant!