Splunk Search

summing up rows by two column

ISP8055
Path Finder

Hi there, 

I have a table with 5 fields. 
E column is numeric value, C is sub category of A

I want to sum E by column C AND column A.

A B C D E
a     x       30

a     y       20

a     x       40

b    y        10

b    x        40


if I do stats(sum E) by A = it will give output of sum of first three rows of E.
if I do stats(sum E) by c = it will give output of rows by x and by e. 
I want to output be like a x 50  ( 50 is 30 + 20 in this case)

Hope, I conveyed what I'm going for.

 

Labels (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

I think what you want is ...

 

| stats sum(E) by A, C

 

And that should give you your answer.  (I think you miscalculated your example.  ax should be 30+40=70 and is the first and third lines, right?).

The output I get is

 

A	C	sum(E)
a	x	70
a	y	20
b	x	40
b	y	10

 

And the run-anywhere search you can test with yourself was:

 

| makeresults 
| eval testData = "a,x,30 a,y,20 a,x,40 b,y,10 b,x,40"
| makemv delim=" " testData
| mvexpand testData
| makemv delim="," testData
| eval A = mvindex(testData, 0), C = mvindex(testData,1), E = mvindex(testData, 2)
| stats sum(E) by A, C

 

Happy Splunking!

-Rich

View solution in original post

Richfez
SplunkTrust
SplunkTrust

I think what you want is ...

 

| stats sum(E) by A, C

 

And that should give you your answer.  (I think you miscalculated your example.  ax should be 30+40=70 and is the first and third lines, right?).

The output I get is

 

A	C	sum(E)
a	x	70
a	y	20
b	x	40
b	y	10

 

And the run-anywhere search you can test with yourself was:

 

| makeresults 
| eval testData = "a,x,30 a,y,20 a,x,40 b,y,10 b,x,40"
| makemv delim=" " testData
| mvexpand testData
| makemv delim="," testData
| eval A = mvindex(testData, 0), C = mvindex(testData,1), E = mvindex(testData, 2)
| stats sum(E) by A, C

 

Happy Splunking!

-Rich

ISP8055
Path Finder

You are correct. it should be 70. Sorry, typo on my end.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...