sum( ) Query Function

Calculates the sum for a field over a set of events. Result is returned in a field named _sum

Parameters

Name Type Required Default Description
field string Yes field to extract a number from and sum over”
as string No _sum name of output field

field is the unnamed parameter.

Examples

How many bytes did our webserver send per minute

bucket(function=sum(bytes_sent))