Calculates the sum for a field over a set of events. Result is returned in a field named _sum.
Function Summary| Signature | sum([as], field) |
| Output Data | Zero or One Event |
| Function Type | Aggregate |
| Incompatible | Filter Alerts |
sum()Hide omitted argument names for this function
Omitted Argument NamesThe argument name for
fieldcan be omitted; the following forms of this function are equivalent:logscale Syntaxsum("value")and:
logscale Syntaxsum(field="value")These examples show basic structure only.
sum() Syntax Examples
How many bytes did our webserver send per minute
bucket(function=sum(bytes_sent))sum() Examples
Click next to an example below to get the full details.
Bucket Events Into Groups
Bucket events into 24 groups using the
count() function and
bucket() function
Query
bucket(buckets=24, function=sum("count"))
| parseTimestamp(field=_bucket,format=millis)Introduction
In this example, the bucket() function is used to
request 24 buckets over a period of one day in the
humio-metrics repository.
Step-by-Step
Starting with the source repository events.
- logscale
bucket(buckets=24, function=sum("count"))Buckets the events into 24 groups spanning over a period of one day, using the
sum()function on the count field. - logscale
| parseTimestamp(field=_bucket,format=millis)Extracts the timestamp from the generated bucket and converts the timestamp to a date time value. In this example, the bucket outputs the timestamp as an epoch value in the _bucket field. This results in an additional bucket containing all the data after the requested timespan for the requested number of buckets.
Event Result set.
Summary and Results
The query is used to optimizing data storage and query performance by making et easier to manage and locate data subsets when performing analytics tasks. Note that the resulting outputs shows 25 buckets; the original requested 24 buckets and in addition the bucket for the extracted timestamp.
Sample output from the incoming example data:
| _bucket | _sum | @timestamp |
|---|---|---|
| 1681290000000 | 1322658945428 | 1681290000000 |
| 1681293600000 | 1879891517753 | 1681293600000 |
| 1681297200000 | 1967566541025 | 1681297200000 |
| 1681300800000 | 2058848152111 | 1681300800000 |
| 1681304400000 | 2163576682259 | 1681304400000 |
| 1681308000000 | 2255771347658 | 1681308000000 |
| 1681311600000 | 2342791941872 | 1681311600000 |
| 1681315200000 | 2429639369980 | 1681315200000 |
| 1681318800000 | 2516589869179 | 1681318800000 |
| 1681322400000 | 2603409167993 | 1681322400000 |
| 1681326000000 | 2690189000694 | 1681326000000 |
| 1681329600000 | 2776920777654 | 1681329600000 |
| 1681333200000 | 2873523432202 | 1681333200000 |
| 1681336800000 | 2969865160869 | 1681336800000 |
| 1681340400000 | 3057623890645 | 1681340400000 |
| 1681344000000 | 3144632647026 | 1681344000000 |
| 1681347600000 | 3231759376472 | 1681347600000 |
| 1681351200000 | 3318929777092 | 1681351200000 |
| 1681354800000 | 3406027872076 | 1681354800000 |
| 1681358400000 | 3493085788508 | 1681358400000 |
| 1681362000000 | 3580128551694 | 1681362000000 |
| 1681365600000 | 3667150316470 | 1681365600000 |
| 1681369200000 | 3754207997997 | 1681369200000 |
| 1681372800000 | 3841234050532 | 1681372800000 |
| 1681376400000 | 1040019734927 | 1681376400000 |
Calculate Total Log Volume Per Service
Analyze log volume across services using the
groupBy() function with
sum()
Query
event_type="log_event"
| groupBy([service], function=sum(field="bytes", as=TotalBytes))
| sort(field="TotalBytes", order="desc")Introduction
In this example, the groupBy() is used with
sum() to calculate total log volume per service,
then sorted to identify which services generate the most data.
Example incoming data might look like this:
| @timestamp | event_type | service | bytes |
|---|---|---|---|
| 1686837825000 | log_event | auth-service | 4200 |
| 1686837825000 | log_event | api-gateway | 15800 |
| 1686837825000 | log_event | auth-service | 3100 |
| 1686837826000 | log_event | billing-service | 9200 |
| 1686837826000 | log_event | api-gateway | 22400 |
| 1686837826000 | log_event | auth-service | 5600 |
| 1686837827000 | log_event | payment-service | 18300 |
| 1686837827000 | log_event | billing-service | 7800 |
| 1686837827000 | log_event | api-gateway | 19200 |
| 1686837828000 | log_event | payment-service | 21000 |
| 1686837828000 | log_event | billing-service | 6400 |
| 1686837828000 | log_event | auth-service | 4800 |
Step-by-Step
Starting with the source repository events.
- logscale
event_type="log_event"Filters events to include only those where event_type equals
log_event. - logscale
| groupBy([service], function=sum(field="bytes", as=TotalBytes))Groups the data by the service field and calculates the sum of bytes, storing the result in a field named TotalBytes.
- logscale
| sort(field="TotalBytes", order="desc")Sorts the results based on the TotalBytes field in descending order (
order=desc), showing services with the highest log volume first. Event Result set.
Summary and Results
The query is used to analyze log volume across services, ranked from highest to lowest.
This query is useful, for example, to identify services generating disproportionate log volume, plan ingestion capacity, or investigate unexpected spikes in data output.
Sample output from the incoming example data:
| service | TotalBytes |
|---|---|
| api-gateway | 57400 |
| payment-service | 39300 |
| billing-service | 23400 |
| auth-service | 17700 |
Note that the volume values are in bytes and that each row represents the aggregated log volume for a unique service.