<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tstats aggragate function not returning results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636554#M221069</link>
    <description>&lt;P&gt;Check datamodel definition to see the data type for the field Latency whether it's a number or string. Avg works with numbers.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2023 15:05:59 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2023-03-29T15:05:59Z</dc:date>
    <item>
      <title>Why is tstats aggragate function not returning results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636549#M221065</link>
      <description>&lt;P&gt;So I'm fairly new to using data models for my visuals, and converting my network performance dashboard to summarized data model searched. My visuals for error rate and request volume worked easily, but latency not so much. Here's the search I am attempting:&lt;/P&gt;
&lt;P&gt;| tstats summariesonly=t avg(All_Performance.Network.latency) from datamodel=Performance.All_Performance where nodename=All_Performance.Network BY _time span=15s&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here are searches that work:&lt;/P&gt;
&lt;P&gt;| tstats summariesonly=t count(All_Performance.Network.latency) from datamodel=Performance.All_Performance where nodename=All_Performance.Network BY _time span=15s&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;| from datamodel Performance.Network | timechart span=15s avg(latency) as latency&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone explain why tstats count() works here, but not min, avg, max, etc?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 16:01:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636549#M221065</guid>
      <dc:creator>lnvaderzee</dc:creator>
      <dc:date>2023-03-29T16:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: tstats aggragate function not returning results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636554#M221069</link>
      <description>&lt;P&gt;Check datamodel definition to see the data type for the field Latency whether it's a number or string. Avg works with numbers.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 15:05:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636554#M221069</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2023-03-29T15:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: tstats aggragate function not returning results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636555#M221070</link>
      <description>&lt;P&gt;That was actually my first thought. I checked and when I made the field I did in fact have it as string, but changed it and rebuilt the acceleration. So it wasn't that&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 15:16:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-tstats-aggragate-function-not-returning-results/m-p/636555#M221070</guid>
      <dc:creator>lnvaderzee</dc:creator>
      <dc:date>2023-03-29T15:16:37Z</dc:date>
    </item>
  </channel>
</rss>

