Splunk Search

## timechart sum

Communicator

``````index="acoe_np_spa_metrics"
| search Project="*" AND Volume="*"
| timechart span=1mon count(eval(D_Status="F")) as success_count
count(eval(D_Status="S")) as failure_count count as Total
| eval STP=(success_count/Total)*100
| fields - Total``````

Good day, I have the above SPL query it gives me the count of "F"s and "S"s but I need the sum of Volumes where D_Status = F and sum of Volume where D_Status = S

Labels (3)

• ### fields

1 Solution
SplunkTrust

``````index="acoe_np_spa_metrics"
| search Project="*" AND Volume="*"
| timechart span=1mon sum(eval(if(D_Status="F",Volume,0))) as success_count
count(eval(if(D_Status="S",Volume,0))) as failure_count count as Total
| eval STP=(success_count/Total)*100
| fields - Total``````

Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

SplunkTrust

``````index="acoe_np_spa_metrics"
| search Project="*" AND Volume="*"
| timechart span=1mon sum(eval(if(D_Status="F",Volume,0))) as success_count
count(eval(if(D_Status="S",Volume,0))) as failure_count count as Total
| eval STP=(success_count/Total)*100
| fields - Total``````

Thanks
KV
▄︻̷̿┻̿═━一

If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.

Did you miss .conf21 Virtual?

### Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE! Catch Up Now >>

Get Updates on the Splunk Community!