Hello,
How can i sum fields to have the total in a new field ?
For example, i have a field called (BytesReceivedPerSec) and i would have the sum of this field for all the event (in realtime)
I tried accum BytesReceivedPersec AS bytesrcvdtotal but i doesn't do a total sum of all the bytes received.
Have you an idea ?
Thanks
Try the following search:
index=Your_Index | stats sum(BytesReceivedPerSec) AS bytes_total
Thank you very much 🙂
It works perfectly
my search exactly :
host=hp-dev index="main"| stats sum(BytesReceivedPersec) AS octets_recus sum(BytesSentPersec) AS octets_envoyes | eval octets_recus_Mo=octets_recus / 1000000 | eval octets_envoyes_Mo=octets_envoyes / 1000000
Glad to help 🙂
Try the following search:
index=Your_Index | stats sum(BytesReceivedPerSec) AS bytes_total