Splunk Search

sum the 3 numbers in a eval statement?

splunkranger
Path Finder

my search returns 3 numbers

acount, bcount, ccount
1 0 1
2 4 3

I would like to be able use eval to create a sum of these three fields, is this possible?

eval totalcount=acount+bcount+ccount?

Sorry if this is not very clear..

thank you,

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

yes, it works.
eval totalcount=acount+bcount+ccount

or if you want to sum all the columns, use the command
| addtotals

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That's more than possible, with precisely the eval call you posted.

Is there more to the question than that?

0 Karma

splunkranger
Path Finder

Thank you, however for some reason I was not getting a result. addtotals is working for me.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...