Splunk Search

Sum of two fields

tej8
New Member

I have two fields "body.response.successfulItemsCount" & "body.successfulItemsCount". I need sum of total of these two fields.

I ran separate queries like this : 1. index= AND | chart sum("body.response.successfulItemsCount") as sum
2. index= AND ** | chart sum("body.successfulItemsCount") as sum

I got accurate result when i run these queries , but how to get total sum of results in one query? I tried this one but not working
index= AND | chart sum("body.response.successfulItemsCount" OR "body.successfulItemsCount") as sum

Tags (1)
0 Karma

whrg
Motivator

Hello @tej8,

Try something like this:

your base search
| stats sum("body.response.successfulItemsCount") AS sum1 sum("body.successfulItemsCount") AS sum2
| eval totalsum = sum1 + sum2
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...