Splunk Search

How do I append a column to a chart?

j_partsch
Explorer

I have the following search

index=firewall policy_name="/Common/default" request_status=blocked (violations="Access from malicious IP address" OR violations="Web scraping detected") | chart count over date_mday by violations

which gives the following chart
date_mday Access from malicious IP address Web scraping detected
14 18951 65
15 16891 176
but what I want is
date_mday Access from malicious IP address Web scraping detected Total
14 18951 65 19016
15 16891 176 17067

0 Karma
1 Solution

elliotproebstel
Champion

I think this should do it:
| addtotals "Access from malicious IP address" "Web scraping detected" fieldname=Total

View solution in original post

0 Karma

elliotproebstel
Champion

I think this should do it:
| addtotals "Access from malicious IP address" "Web scraping detected" fieldname=Total

0 Karma

j_partsch
Explorer

This worked exactly the way I needed. Thank you!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...