Splunk sum is not working. That means its output is very different from its input.

Splunk sum is not working. Oct 23, 2017 · But once I run the command sum (DomesticAmount), it gives me a completely different answer than what I know should be. I've had a play using the below SPL to create some sample data and I think it now gives the result expected? Jan 30, 2023 · Can you do a sum(status) before the count within the chart to get the desired result? Oct 25, 2016 · Asset_status sum (count) Desktop Others Server May i please know the reason for this and how can i get the sum of counts values. If you just want a count (not sum) of values either fulfilling one condition or the other, you have to simply do two separate aggregations. The first stats command tries to sum the count field, but that field does not exist. Do you love big data and cannot lie? Need to take the SH out of IT? Need a ninja but they are too busy? If so, then you are in the right place! This is a place to discuss Splunk, the big data analytics software. This is why scount_by_name is empty. That means its output is very different from its input. Jul 18, 2023 · It doesn't work like that. . Feb 17, 2025 · The reason you're having an issue here is you're using "comparison" which is a string value - get rid of the double quotes and it will reference the field. More importantly, however, stats is a transforming command. On one of the occasions, a warning showed up stating that some values may have been truncated or ignored. Ask questions, share tips, build apps! Sep 28, 2021 · There are a couple of issues here. bzcelj tgxnps adoglj vnjb brrbv jmq usd vyb lddjpxl jqaz

Write a Review Report Incorrect Data