Splunk Cloud

Search Reference

Download manual as PDF

Download topic as PDF



For each event where field is a number, the accum command calculates a running total or sum of the numbers. The accumulated sum can be returned to either the same field, or a newfield that you specify.


accum <field> [AS <newfield>]

Required arguments

Syntax: <string>
Description: The name of the field that you want to calculate the accumulated sum for. The field must contain numeric values.

Optional arguments

Syntax: <string>
Description: The name of a new field where you want the results placed.


Example 1:

Save the running total of the quantity field into a new field called "total_quantity".

... | accum quantity AS total_quantity

See also

autoregress, delta, streamstats, trendline


Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the accum command.


This documentation applies to the following versions of Splunk Cloud: 6.5.0, 6.5.1, 6.6.0, 6.5.1612, 6.6.1, 6.6.3, 7.0.0


Thank you for the suggestion. I will pass it along to the engineering team.

Lstewart splunk, Splunker
June 23, 2017

This command *REALLY* needs a "BY" option (like stats).

June 23, 2017

Woodcock - It is the same without the reverse command.

Lstewart splunk, Splunker
December 3, 2015

I assume that your example is the same as doing this, right?

... | reverse | streamstats current=t sum(quantity) AS total_quantity

July 9, 2015

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters