Splunk Search

sum the 3 numbers in a eval statement?

splunkranger
Path Finder

my search returns 3 numbers

acount, bcount, ccount
1 0 1
2 4 3

I would like to be able use eval to create a sum of these three fields, is this possible?

eval totalcount=acount+bcount+ccount?

Sorry if this is not very clear..

thank you,

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

yes, it works.
eval totalcount=acount+bcount+ccount

or if you want to sum all the columns, use the command
| addtotals

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That's more than possible, with precisely the eval call you posted.

Is there more to the question than that?

0 Karma

splunkranger
Path Finder

Thank you, however for some reason I was not getting a result. addtotals is working for me.

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...