Splunk Search

How would I remove duplicates but add up their counts?

Ragate
Explorer

I have two sources of data. One that has an Account Name, License Key, and Account Revenue. The other has License Key and an Item_Count field.
Current it shows like this
LicenseKey Item_Count
200IGN3 4
200IGN3 10
342mD3D 8
342mD3D 6

I would like to remove the duplicate keys and add up there item counts.

How would this be done?
Thanks in advance.

0 Karma

somesoni2
Revered Legend

Try like this

your current search showing fields LicenseKey Item_Count
| stats sum(Item_Count) as Item_Count by LicenseKey
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...