Splunk Search

where clause with a variable

SanthoshSreshta
Contributor

Hi.

I need to get sum of total_revenue where churn=1.
I am able to get the count of churn whose churn=1 and total count of chur but not for other variable total_revenue.
Can any one help me out to achieve this

I used the query to get count churn=1 :
sourcetype="Customer_Churn"

| eval CHURN = if(CHURN="1",1,0)
| stats sum(CHURN) as Churned_Customers,count(CHURN) as Total_Churn by PLACEMENT

Thanks,
Santhosh.

0 Karma
1 Solution

vganjare
Builder
0 Karma

vganjare
Builder

change stats to eventstats. Splunk has where command @ http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Where

0 Karma

SanthoshSreshta
Contributor

Thank you @vganjare
sourcetype="Customer_Churn"

| eventstats sum(Total_Revenue) as ff by PLACEMENT
| where CHURN="1"
| stats sum(Total_Revenue) by PLACEMENT

0 Karma

SanthoshSreshta
Contributor

@vganjare, Can we able to get sum(total_revenue) without any condition. in the same query.

0 Karma

vganjare
Builder

using eventstats, all the events are updated with new fields i.e. if you use eventstats sum(Total_Revenue) , then all the events will have same value for sum field. More @ http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Eventstats

vganjare
Builder

Hi,

Not able to understand the question. Can you please elaborate?

Thanks,
Vishal

0 Karma

SanthoshSreshta
Contributor

I need the sum(total_revenue) where churn=1.
I have two variable total revenue and churn. churn has two values 1 and 0.
like in SQL: select sum(total_variable) from my_source_table where churn=1

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...