<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Average Duration and 95 percentile duration using summary index in Security</title>
    <link>https://community.splunk.com/t5/Security/Average-Duration-and-95-percentile-duration-using-summary-index/m-p/327494#M8398</link>
    <description>&lt;P&gt;1) The biggest problem is "&lt;CODE&gt;values(duration)&lt;/CODE&gt;".   &lt;CODE&gt;Values&lt;/CODE&gt; eliminates duplicates, so the average and percentiles will never be calculated correctly.  &lt;/P&gt;

&lt;P&gt;2) Use &lt;CODE&gt;sistats&lt;/CODE&gt;, not &lt;CODE&gt;stats&lt;/CODE&gt;, to populate a summary index.  It will keep the "shape" of the underlying data.&lt;/P&gt;

&lt;P&gt;See this page for more tips, and a link to a video - &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Knowledge/Usesummaryindexing"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Knowledge/Usesummaryindexing&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jun 2017 21:29:30 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2017-06-05T21:29:30Z</dc:date>
    <item>
      <title>Average Duration and 95 percentile duration using summary index</title>
      <link>https://community.splunk.com/t5/Security/Average-Duration-and-95-percentile-duration-using-summary-index/m-p/327493#M8397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a query like this:&lt;/P&gt;

&lt;P&gt;(splunk_server="serverA" OR splunk_server="serverB") (app="Cargo" OR app="Customer") index="dev-cargo-app" env="DEV" site=* (sourcetype=app:Cargo:Performance) ms | stats avg(duration) as avgdur, perc95(duration) as 95perc&lt;/P&gt;

&lt;P&gt;I am trying to make it more efficient using summary indexing:&lt;/P&gt;

&lt;P&gt;Summary index:&lt;BR /&gt;
(splunk_server="serverA" OR splunk_server="serverB") (app="Cargo" OR app="Customer") index="dev-cargo-app" env="DEV" site=* (sourcetype=app:Cargo:Performance OR sourcetype=app:Customer:Performance) ms &lt;BR /&gt;
| stats count(_raw) as "No. of Events",values(duration) as "Duration" by app, site, sourcetype, category, _time&lt;/P&gt;

&lt;P&gt;My 'efficient' query is:&lt;BR /&gt;
index= summary report="summary_index_name" | search sourcetype=app:Cargo:Performance &lt;BR /&gt;
| stats avg(Duration) as avgdur, perc95(Duration) as 95perc&lt;/P&gt;

&lt;P&gt;Average duration is calculated correctly, but perc95(Duration) does not match.&lt;/P&gt;

&lt;P&gt;My 'efficient query' gives me 100 &amp;gt; normal query for perc95(Duration).&lt;/P&gt;

&lt;P&gt;Is it not possible to calculate perc95(Duration) using summary index?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Deepak&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Average-Duration-and-95-percentile-duration-using-summary-index/m-p/327493#M8397</guid>
      <dc:creator>deepak02</dc:creator>
      <dc:date>2020-09-29T14:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Average Duration and 95 percentile duration using summary index</title>
      <link>https://community.splunk.com/t5/Security/Average-Duration-and-95-percentile-duration-using-summary-index/m-p/327494#M8398</link>
      <description>&lt;P&gt;1) The biggest problem is "&lt;CODE&gt;values(duration)&lt;/CODE&gt;".   &lt;CODE&gt;Values&lt;/CODE&gt; eliminates duplicates, so the average and percentiles will never be calculated correctly.  &lt;/P&gt;

&lt;P&gt;2) Use &lt;CODE&gt;sistats&lt;/CODE&gt;, not &lt;CODE&gt;stats&lt;/CODE&gt;, to populate a summary index.  It will keep the "shape" of the underlying data.&lt;/P&gt;

&lt;P&gt;See this page for more tips, and a link to a video - &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Knowledge/Usesummaryindexing"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Knowledge/Usesummaryindexing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 21:29:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Average-Duration-and-95-percentile-duration-using-summary-index/m-p/327494#M8398</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-06-05T21:29:30Z</dc:date>
    </item>
  </channel>
</rss>

