Splunk Search

How do I add a number to addColTotals?

karunanaik
Engager

Here is my search query

index=nonprod CFE_AppName=abc
CFE_Environment=dev Appointment has
been booked | rex field=_raw
"Appointment has been booked
dept: (?.*)" | stats
count by dept | addColTotals

How can I add a static number to addColTotals? For example if addColTotals is 30 then I want to display 30+100 which is 130.

Tags (1)
1 Solution

woodcock
Esteemed Legend

Like this:

| windbag 
| rename lang AS dept 

| stats count BY dept 
| addcoltotals
| fillnull value="GRAND_TOTAL" dept
| eval count = count + if(dept=="GRAND_TOTAL", 100, 0)

View solution in original post

woodcock
Esteemed Legend

Like this:

| windbag 
| rename lang AS dept 

| stats count BY dept 
| addcoltotals
| fillnull value="GRAND_TOTAL" dept
| eval count = count + if(dept=="GRAND_TOTAL", 100, 0)

aberkow
Builder

Does this example make sense? You should be using dept instead of _time for yours:

| makeresults count=3
| streamstats count
| addcoltotals
| eval _time=if(isnull(_time), "addcoltotalscolumn", _time)
| eval count=if(_time="addcoltotalscolumn", count+100, count)

Essentially, you find the column that corresponds to the addtotalscolumn (it should have a null department, I then tag it with a string), and then add 100 to the count for that row. You can also do this in one line w/

| eval count=if(isnull(_time), count+100, count), but this is a bit harder to understand what's going on!

Hope this helps

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...