<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help Regarding search query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601659#M209393</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have following splunk query.&lt;BR /&gt;&lt;BR /&gt;| dbxquery connection="FFconed_feTenant" query="select count(file_name) as file_count, DATE_FORMAT(created_at,\"%m/%d/%y %W\") as date from ida_files_inventory&lt;BR /&gt;where created_at &amp;gt; Date_sub(Curdate(), INTERVAL 7 Day) and created_at &amp;lt; Curdate() group by DATE_FORMAT(created_at,\"%m/%d/%y %W\")"&lt;/P&gt;
&lt;P&gt;It gives me the per-day count of files received in last 7 days along with the date. The result is as follows.&lt;/P&gt;
&lt;P&gt;date&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file_count&lt;BR /&gt;06/07/22 Tuesday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 79&lt;BR /&gt;06/08/22 Wednesday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;46&lt;BR /&gt;06/09/22 Thursday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 57&lt;BR /&gt;06/10/22 Friday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5&lt;BR /&gt;06/11/22 Saturday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5&lt;BR /&gt;06/12/22 Sunday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 227&lt;BR /&gt;06/13/22 Monday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 187&lt;/P&gt;
&lt;P&gt;I want to calculate the running averages of file_counts for all these days.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For e.g.&lt;BR /&gt;for 1st day, running average is 79/1 = 79&lt;BR /&gt;for 2nd day, running average is 79+46/2 = 62.5&lt;BR /&gt;for 3rd day, running average is 79+46+57/3 = 60.67&lt;BR /&gt;and so on.&lt;/P&gt;
&lt;P&gt;For this I want to write a query. Please help me with this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2022 16:25:58 GMT</pubDate>
    <dc:creator>devdattajogleka</dc:creator>
    <dc:date>2022-06-14T16:25:58Z</dc:date>
    <item>
      <title>Help Regarding search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601659#M209393</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have following splunk query.&lt;BR /&gt;&lt;BR /&gt;| dbxquery connection="FFconed_feTenant" query="select count(file_name) as file_count, DATE_FORMAT(created_at,\"%m/%d/%y %W\") as date from ida_files_inventory&lt;BR /&gt;where created_at &amp;gt; Date_sub(Curdate(), INTERVAL 7 Day) and created_at &amp;lt; Curdate() group by DATE_FORMAT(created_at,\"%m/%d/%y %W\")"&lt;/P&gt;
&lt;P&gt;It gives me the per-day count of files received in last 7 days along with the date. The result is as follows.&lt;/P&gt;
&lt;P&gt;date&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file_count&lt;BR /&gt;06/07/22 Tuesday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 79&lt;BR /&gt;06/08/22 Wednesday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;46&lt;BR /&gt;06/09/22 Thursday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 57&lt;BR /&gt;06/10/22 Friday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5&lt;BR /&gt;06/11/22 Saturday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5&lt;BR /&gt;06/12/22 Sunday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 227&lt;BR /&gt;06/13/22 Monday&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 187&lt;/P&gt;
&lt;P&gt;I want to calculate the running averages of file_counts for all these days.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For e.g.&lt;BR /&gt;for 1st day, running average is 79/1 = 79&lt;BR /&gt;for 2nd day, running average is 79+46/2 = 62.5&lt;BR /&gt;for 3rd day, running average is 79+46+57/3 = 60.67&lt;BR /&gt;and so on.&lt;/P&gt;
&lt;P&gt;For this I want to write a query. Please help me with this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 16:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601659#M209393</guid>
      <dc:creator>devdattajogleka</dc:creator>
      <dc:date>2022-06-14T16:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601662#M209394</link>
      <description>&lt;LI-CODE lang="markup"&gt;| streamstats count sum(file_count) as total
| eval average=round(total/count,1)&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 14 Jun 2022 06:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601662#M209394</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-06-14T06:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Regarding search query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601679#M209405</link>
      <description>&lt;P&gt;Hi . this query should be worked for you :&lt;BR /&gt;| streamstats count,sum(file_count) as total_sum | eval avg=total_sum/count&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 08:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-Regarding-search-query/m-p/601679#M209405</guid>
      <dc:creator>marysan</dc:creator>
      <dc:date>2022-06-14T08:30:41Z</dc:date>
    </item>
  </channel>
</rss>

