Calculates the sum for a field over a set of events. Result is returned in a field named _sum.

Function Summary
Signaturesum([as], field)
Output DataZero or One Event
Function TypeAggregate
IncompatibleFilter Alerts
Parameters for sum()
ParameterTypeInterpreted TypeRequiredDefault ValueDescription
asstringfieldnameoptional[a] _sum Name of output field.
field[b]stringfieldnamerequired ย  Field to extract a number from and sum over.

[a] Optional parameters use their default value unless explicitly set.

[b] The parameter name field can be omitted.

Hide omitted argument names for this function

Show omitted argument names for this function

sum() Syntax Examples

How many bytes did our webserver send per minute

logscale
bucket(function=sum(bytes_sent))

sum() Examples

Click + next to an example below to get the full details.

Bucket Events Into Groups

Bucket events into 24 groups using the count() function and bucket() function

Query
logscale
bucket(buckets=24, function=sum("count"))
| parseTimestamp(field=_bucket,format=millis)
Introduction

In this example, the bucket() function is used to request 24 buckets over a period of one day in the humio-metrics repository.

Step-by-Step
  1. Starting with the source repository events.

  2. logscale
    bucket(buckets=24, function=sum("count"))

    Buckets the events into 24 groups spanning over a period of one day, using the sum() function on the count field.

  3. logscale
    | parseTimestamp(field=_bucket,format=millis)

    Extracts the timestamp from the generated bucket and converts the timestamp to a date time value. In this example, the bucket outputs the timestamp as an epoch value in the _bucket field. This results in an additional bucket containing all the data after the requested timespan for the requested number of buckets.

  4. Event Result set.

Summary and Results

The query is used to optimizing data storage and query performance by making et easier to manage and locate data subsets when performing analytics tasks. Note that the resulting outputs shows 25 buckets; the original requested 24 buckets and in addition the bucket for the extracted timestamp.

Sample output from the incoming example data:

_bucket_sum@timestamp
168129000000013226589454281681290000000
168129360000018798915177531681293600000
168129720000019675665410251681297200000
168130080000020588481521111681300800000
168130440000021635766822591681304400000
168130800000022557713476581681308000000
168131160000023427919418721681311600000
168131520000024296393699801681315200000
168131880000025165898691791681318800000
168132240000026034091679931681322400000
168132600000026901890006941681326000000
168132960000027769207776541681329600000
168133320000028735234322021681333200000
168133680000029698651608691681336800000
168134040000030576238906451681340400000
168134400000031446326470261681344000000
168134760000032317593764721681347600000
168135120000033189297770921681351200000
168135480000034060278720761681354800000
168135840000034930857885081681358400000
168136200000035801285516941681362000000
168136560000036671503164701681365600000
168136920000037542079979971681369200000
168137280000038412340505321681372800000
168137640000010400197349271681376400000

Calculate Total Log Volume Per Service

Analyze log volume across services using the groupBy() function with sum()

Query
logscale
event_type="log_event"
| groupBy([service], function=sum(field="bytes", as=TotalBytes))
| sort(field="TotalBytes", order="desc")
Introduction

In this example, the groupBy() is used with sum() to calculate total log volume per service, then sorted to identify which services generate the most data.

Example incoming data might look like this:

@timestampevent_typeservicebytes
1686837825000log_eventauth-service4200
1686837825000log_eventapi-gateway15800
1686837825000log_eventauth-service3100
1686837826000log_eventbilling-service9200
1686837826000log_eventapi-gateway22400
1686837826000log_eventauth-service5600
1686837827000log_eventpayment-service18300
1686837827000log_eventbilling-service7800
1686837827000log_eventapi-gateway19200
1686837828000log_eventpayment-service21000
1686837828000log_eventbilling-service6400
1686837828000log_eventauth-service4800
Step-by-Step
  1. Starting with the source repository events.

  2. logscale
    event_type="log_event"

    Filters events to include only those where event_type equals log_event.

  3. logscale
    | groupBy([service], function=sum(field="bytes", as=TotalBytes))

    Groups the data by the service field and calculates the sum of bytes, storing the result in a field named TotalBytes.

  4. logscale
    | sort(field="TotalBytes", order="desc")

    Sorts the results based on the TotalBytes field in descending order (order=desc), showing services with the highest log volume first.

  5. Event Result set.

Summary and Results

The query is used to analyze log volume across services, ranked from highest to lowest.

This query is useful, for example, to identify services generating disproportionate log volume, plan ingestion capacity, or investigate unexpected spikes in data output.

Sample output from the incoming example data:

serviceTotalBytes
api-gateway57400
payment-service39300
billing-service23400
auth-service17700

Note that the volume values are in bytes and that each row represents the aggregated log volume for a unique service.