Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to edit my search to display Min, Max, Total, and Sum at the end of a table as separate rows?

$
0
0
Hi This is my current Splunk search: index=pqaestore source="/log/jboss_jmx_stats.log" | dedup host | rex field=_raw "(?memory=(?\d+))" | rex field=_raw "(?httpthreads=(?\d+))" | rex field=_raw "(?httpsthreads=(?\d+))" | rex field=_raw "(?websessions=(?\d+))" | rex field=_raw "(?ATGAdminDS=(?\d+))" | rex field=_raw "(?ATGCatalogDSA=(?\d+))" | rex field=_raw "(?ATGCatalogDSB=(?\d+))" | rex field=_raw "(?ATGCSCAdminDS=(?\d+))" | rex field=_raw "(?ATGCustDS=(?\d+))" | rex field=_raw "(?ATGOrderDS=(?\d+))" | rex field=_raw "(?ATGPriceDS=(?\d+))" | rex field=_raw "(?ATGSearchDS=(?\d+))" | rex field=_raw "(?DefaultDS=(?\d+))" | rex field=_raw "(?EStoreAdmDS=(?\d+))" | streamstats count as SNo| table SNo host FreeMemory httpthreads httpsthreads websessions ATGAdminDS ATGCatalogDSA ATGCatalogDSB ATGCSCAdminDS ATGCustDS ATGOrderDS ATGPriceDS ATGSearchDS DefaultDS EStoreAdmDS Table output [Removed the host from output as it is sensitive] FreeMemory httpthreads httpsthreads websessions ATGAdminDS ATGCatalogDSA 54 0 0 11 2 2 2 0 5 7 0 0 40 0 0 12 2 2 2 2 5 7 2 0 51 0 0 11 2 2 2 0 5 7 0 0 51 0 0 10 2 2 2 0 5 7 0 0 56 1 0 12 2 2 2 0 5 7 0 0 55 1 0 11 2 2 2 0 5 7 0 0 78 0 0 8 2 2 2 0 5 7 0 0 70 0 0 9 2 2 2 0 5 7 0 0 65 0 0 11 2 2 2 0 5 7 2 0 50 1 0 10 2 2 2 0 5 7 0 0 60 1 0 9 2 2 2 0 5 7 0 0 52 0 0 10 2 2 2 0 5 7 0 0 How to print Total, min, Max, Average at the end of this table as separate rows. Please advise.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>