I have a search returning results in a table with columns for:
date, username, eventcount
I'd like to display subtotals in the table something like this.
Is it possible?
Appendpipe might hold the answers for you;
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Appendpipe
your base search | stats count by date username | appendpipe [stats sum(count) as count by date | eval username = "Total"]
Hope this helps,
Kristian
Appendpipe might hold the answers for you;
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Appendpipe
your base search | stats count by date username | appendpipe [stats sum(count) as count by date | eval username = "Total"]
Hope this helps,
Kristian
eval username = "Totals for " ?
Thanks -- that looks like it'll do the job. Now I just need to figure whether I can get those total rows formatted differently (like shown in bold)...