<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: stats vs eventstats in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309078#M140448</link>
    <description>&lt;P&gt;refer &lt;A href="https://answers.splunk.com/answers/139534/what-are-the-calculated-differences-between-stats-and-eventstats.html"&gt;https://answers.splunk.com/answers/139534/what-are-the-calculated-differences-between-stats-and-eventstats.html&lt;/A&gt;&lt;BR /&gt;
it will show difference between stats and eventstats with example&lt;BR /&gt;
Hope this helps you.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 10:56:05 GMT</pubDate>
    <dc:creator>493669</dc:creator>
    <dc:date>2018-01-17T10:56:05Z</dc:date>
    <item>
      <title>stats vs eventstats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309077#M140447</link>
      <description>&lt;P&gt;I can't comprehend what 'eventstats' is. I went thru the splunk docs.&lt;BR /&gt;I wanna use math functions like avg.. etc.. not sure whether to use stats avg or eventstats avg !!&lt;BR /&gt;An example would be appreciated .&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 04:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309077#M140447</guid>
      <dc:creator>zacksoft</dc:creator>
      <dc:date>2020-06-08T04:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: stats vs eventstats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309078#M140448</link>
      <description>&lt;P&gt;refer &lt;A href="https://answers.splunk.com/answers/139534/what-are-the-calculated-differences-between-stats-and-eventstats.html"&gt;https://answers.splunk.com/answers/139534/what-are-the-calculated-differences-between-stats-and-eventstats.html&lt;/A&gt;&lt;BR /&gt;
it will show difference between stats and eventstats with example&lt;BR /&gt;
Hope this helps you.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 10:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309078#M140448</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-01-17T10:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: stats vs eventstats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309079#M140449</link>
      <description>&lt;P&gt;hey &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;stats&lt;/STRONG&gt; - Calculates aggregate statistics over the results set, such as average, count, and sum. This is similar to SQL aggregation. If stats is used without a by clause only one row is returned, which is the aggregation over the entire incoming result set. If you use a by clause one row is returned for each distinct value specified in the by clause.&lt;BR /&gt;
look this doc &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Stats"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Stats&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;eventstats&lt;/STRONG&gt; - Generate summary statistics of all existing fields in your search results and saves those statistics in to new fields. The eventstats command is similar to the stats command. The difference is that with the eventstats command aggregation results are added inline to each event and added only if the aggregation is pertinent to that event.&lt;BR /&gt;
look this doc &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Eventstats"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Eventstats&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And here is a blog which will tell you the extact difference between them&lt;BR /&gt;
&lt;A href="https://www.splunk.com/blog/2014/04/01/search-command-stats-eventstats-and-streamstats-2.html"&gt;https://www.splunk.com/blog/2014/04/01/search-command-stats-eventstats-and-streamstats-2.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;let me know if this helps !&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 11:08:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309079#M140449</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-01-17T11:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: stats vs eventstats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309080#M140450</link>
      <description>&lt;P&gt;correctly said&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 07:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-vs-eventstats/m-p/309080#M140450</guid>
      <dc:creator>vinitnitdgp</dc:creator>
      <dc:date>2020-04-16T07:18:21Z</dc:date>
    </item>
  </channel>
</rss>

