<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Standard Deviation Total Requests Per Day in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632014#M219524</link>
    <description>&lt;P&gt;By using "| where Number_Of_Requests &amp;gt; 0", you are potentially "skewing" the results, although that does depend on what it is you are trying to show. For example, if you had 5 days, with counts of 2, 0, 0, 0, 3, your mean would be 1 with the zeroes included, and 2.5 without the zeroes. Similarly, the stddev would be similarly affected by the removal or inclusion of the zeroes.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 14:54:53 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-02-23T14:54:53Z</dc:date>
    <item>
      <title>Standard Deviation Total Requests Per Day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632012#M219522</link>
      <description>&lt;P&gt;I am attempting to calculate the following:&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Total Number "Requests Per Day"&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Average/Mean "Requests Per Day"&lt;/P&gt;&lt;P&gt;-&amp;nbsp; Standard Deviation "Requests Per Day"&lt;/P&gt;&lt;P&gt;I am using the following search:&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;index=myCoolIndex cluster_name="myCoolCluster" sourcetype=myCoolSourceType label_app=myCoolApp ("\"statusCode\"") | rex .*\"traceId\"\s:\s\"?(?&amp;lt;traceId&amp;gt;.*?)\".* | dedup traceId | rex "(?s)\"statusCode\"\s:\s\"?(?&amp;lt;statusCode&amp;gt;[245]\d{2})\"?" | timechart span=1d count(statusCode) as "Number_Of_Requests" | where Number_Of_Requests &amp;gt; 0 | eventstats mean(Number_Of_Requests) as "Average Requests Per Day" stdev(Number_Of_Requests) as "Standard Deviation"&lt;/LI-CODE&gt;&lt;P&gt;I am getting results back, but am unsure if the results I am getting back are correct per what I am trying to look for.&amp;nbsp; For instance, I would have thought "stdev()" would need some eval statement to know what the "Total Requests Per Day" and "Average/Mean Requests Per Day" is?&amp;nbsp; &amp;nbsp;Does the "where Number_Of_Requests &amp;gt; 0" skew the results since those are not getting added to the result set?&amp;nbsp; Was hoping someone would be able to take a look at my query and provide a little insight as to what I may still need to do so I can get an accurate Standard Deviation.&amp;nbsp; Also, below is the output I am getting from the current query:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Number_Of_Requests	 Average Requests Per Day   Standard Deviation
	25687	                 64395	                    54741.378572337766
	103103	                 64395	                    54741.378572337766&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 14:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632012#M219522</guid>
      <dc:creator>dickersons</dc:creator>
      <dc:date>2023-02-23T14:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Standard Deviation Total Requests Per Day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632014#M219524</link>
      <description>&lt;P&gt;By using "| where Number_Of_Requests &amp;gt; 0", you are potentially "skewing" the results, although that does depend on what it is you are trying to show. For example, if you had 5 days, with counts of 2, 0, 0, 0, 3, your mean would be 1 with the zeroes included, and 2.5 without the zeroes. Similarly, the stddev would be similarly affected by the removal or inclusion of the zeroes.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 14:54:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632014#M219524</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-02-23T14:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Standard Deviation Total Requests Per Day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632016#M219526</link>
      <description>&lt;P&gt;If I hear what you are saying correctly, then it is likely going to be a more accurate representation of mean and standard deviation if I include the "0" that way every day gets included on the calculation and not only the days in which there are data points?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 14:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632016#M219526</guid>
      <dc:creator>dickersons</dc:creator>
      <dc:date>2023-02-23T14:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Standard Deviation Total Requests Per Day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632020#M219527</link>
      <description>&lt;P&gt;Correct - it is usually more meaningful to include the zeroes, but it does depend on what you are trying to show.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 15:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632020#M219527</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-02-23T15:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Standard Deviation Total Requests Per Day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632025#M219531</link>
      <description>&lt;P&gt;Makes sense.&amp;nbsp; Does the formula itself look legit?&amp;nbsp; Meaning assuming the search criteria is correct and I should get the correct standard deviation based on Requests Per Day?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 15:26:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632025#M219531</guid>
      <dc:creator>dickersons</dc:creator>
      <dc:date>2023-02-23T15:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Standard Deviation Total Requests Per Day</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632029#M219534</link>
      <description>&lt;P&gt;Yes, you will get the mean and standard deviation of all the daily counts in your time period.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 15:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-Total-Requests-Per-Day/m-p/632029#M219534</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-02-23T15:38:17Z</dc:date>
    </item>
  </channel>
</rss>

