<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Calculating Variance of a group leaving one ID at a time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640855#M222032</link>
    <description>&lt;P&gt;Not sure if this is feasible with your data, but try this dirty workaround (anything before "| table LoginID..." is to generate sample data, replace it with your search).&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval raw="1	10thApril	O1	S1	1.39#
2	11thApril	O2	S2	1.76#
3	12thApril	O1	S1	2.45#
4	10thApril	O1	S1	5.67#
5	11thApril	O2	S2	2.34#
6	12thApril	O1	S1	1.23#
7	13thApril	O2	S2	2.56" 
| makemv raw delim="#" 
| mvexpand raw 
| rename raw as _raw 
| rex "(?&amp;lt;LoginID&amp;gt;\S+)\s+(?&amp;lt;AccessDate&amp;gt;\S+)\s+(?&amp;lt;Organization&amp;gt;\S+)\s+(?&amp;lt;Section&amp;gt;\S+)\s+(?&amp;lt;logCount&amp;gt;\S+)" 
| table LoginID AccessDate Organization Section logCount 
| eval idCount=LoginID."#".logCount 
| eventstats values(idCount) as idCounts 
| streamstats count as sno 
| eval idCounts=if(sno&amp;gt;1,mvappend(mvindex(idCounts,0,sno-2),mvindex(idCounts,sno,-1)),mvindex(idCounts,1,-1)) 
| rex field=idCounts "(?&amp;lt;LoginIds&amp;gt;\S+)#(?&amp;lt;logCounts&amp;gt;\S+)" 
| table LoginID Organization Section LoginIds logCounts&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 15:39:00 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2023-04-20T15:39:00Z</dc:date>
    <item>
      <title>How to calculate variance of a group leaving one ID at a time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640606#M221952</link>
      <description>&lt;P&gt;I have the data as below:&lt;/P&gt;
&lt;TABLE width="411"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="72"&gt;LoginID&amp;nbsp;&lt;/TD&gt;
&lt;TD width="95"&gt;AccessDate&lt;/TD&gt;
&lt;TD width="100"&gt;Organization&lt;/TD&gt;
&lt;TD width="72"&gt;Section&lt;/TD&gt;
&lt;TD width="72"&gt;logCount&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;10thApril&lt;/TD&gt;
&lt;TD&gt;O1&lt;/TD&gt;
&lt;TD&gt;S1&lt;/TD&gt;
&lt;TD&gt;1.39&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;11thApril&lt;/TD&gt;
&lt;TD&gt;O2&lt;/TD&gt;
&lt;TD&gt;S2&lt;/TD&gt;
&lt;TD&gt;1.76&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;12thApril&lt;/TD&gt;
&lt;TD&gt;O1&lt;/TD&gt;
&lt;TD&gt;S1&lt;/TD&gt;
&lt;TD&gt;2.45&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;4&lt;/TD&gt;
&lt;TD&gt;10thApril&lt;/TD&gt;
&lt;TD&gt;O1&lt;/TD&gt;
&lt;TD&gt;S1&lt;/TD&gt;
&lt;TD&gt;5.67&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;5&lt;/TD&gt;
&lt;TD&gt;11thApril&lt;/TD&gt;
&lt;TD&gt;O2&lt;/TD&gt;
&lt;TD&gt;S2&lt;/TD&gt;
&lt;TD&gt;2.34&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;12thApril&lt;/TD&gt;
&lt;TD&gt;O1&lt;/TD&gt;
&lt;TD&gt;S1&lt;/TD&gt;
&lt;TD&gt;1.23&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;7&lt;/TD&gt;
&lt;TD&gt;13thApril&lt;/TD&gt;
&lt;TD&gt;O2&lt;/TD&gt;
&lt;TD&gt;S2&lt;/TD&gt;
&lt;TD&gt;2.56&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to calculate variance corresponding to each LoginID leaving that id for the time,&lt;/P&gt;
&lt;P&gt;See Below (The result that is expected):&lt;/P&gt;
&lt;TABLE width="577"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="72"&gt;Id&lt;/TD&gt;
&lt;TD width="95"&gt;Organization&lt;/TD&gt;
&lt;TD width="100"&gt;Section&lt;/TD&gt;
&lt;TD width="107"&gt;values(LoginID)&lt;/TD&gt;
&lt;TD width="131"&gt;values(logCount)&lt;/TD&gt;
&lt;TD width="72"&gt;Variance&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;O1&lt;/TD&gt;
&lt;TD&gt;S1&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;1.76&lt;/TD&gt;
&lt;TD&gt;2.011847&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;2.45&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;4&lt;/TD&gt;
&lt;TD&gt;5.67&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;5&lt;/TD&gt;
&lt;TD&gt;2.34&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;1.23&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;7&lt;/TD&gt;
&lt;TD&gt;2.56&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;O2&lt;/TD&gt;
&lt;TD&gt;S2&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;1.39&lt;/TD&gt;
&lt;TD&gt;2.142889&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;2.45&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;4&lt;/TD&gt;
&lt;TD&gt;5.67&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;5&lt;/TD&gt;
&lt;TD&gt;2.34&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;1.23&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;TD&gt;7&lt;/TD&gt;
&lt;TD&gt;2.56&lt;/TD&gt;
&lt;TD&gt;　&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 20 Apr 2023 16:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640606#M221952</guid>
      <dc:creator>Veerendra</dc:creator>
      <dc:date>2023-04-20T16:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Calculating Variance of a group leaving one ID at a time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640607#M221953</link>
      <description>Please help me in writing the search</description>
      <pubDate>Wed, 19 Apr 2023 14:00:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640607#M221953</guid>
      <dc:creator>Veerendra</dc:creator>
      <dc:date>2023-04-19T14:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Calculating Variance of a group leaving one ID at a time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640614#M221957</link>
      <description>&lt;P&gt;How is variance column value created? What does this report represent?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 14:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640614#M221957</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2023-04-19T14:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Calculating Variance of a group leaving one ID at a time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640822#M222021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Its the variance that can be calculated with varp function in splunk.&lt;BR /&gt;The main issue here is i want LoginID and remaining LoginIDs of that Organization in the same row.&lt;BR /&gt;Please help me there , variance i can calculate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 12:23:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640822#M222021</guid>
      <dc:creator>Veerendra</dc:creator>
      <dc:date>2023-04-20T12:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Calculating Variance of a group leaving one ID at a time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640855#M222032</link>
      <description>&lt;P&gt;Not sure if this is feasible with your data, but try this dirty workaround (anything before "| table LoginID..." is to generate sample data, replace it with your search).&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval raw="1	10thApril	O1	S1	1.39#
2	11thApril	O2	S2	1.76#
3	12thApril	O1	S1	2.45#
4	10thApril	O1	S1	5.67#
5	11thApril	O2	S2	2.34#
6	12thApril	O1	S1	1.23#
7	13thApril	O2	S2	2.56" 
| makemv raw delim="#" 
| mvexpand raw 
| rename raw as _raw 
| rex "(?&amp;lt;LoginID&amp;gt;\S+)\s+(?&amp;lt;AccessDate&amp;gt;\S+)\s+(?&amp;lt;Organization&amp;gt;\S+)\s+(?&amp;lt;Section&amp;gt;\S+)\s+(?&amp;lt;logCount&amp;gt;\S+)" 
| table LoginID AccessDate Organization Section logCount 
| eval idCount=LoginID."#".logCount 
| eventstats values(idCount) as idCounts 
| streamstats count as sno 
| eval idCounts=if(sno&amp;gt;1,mvappend(mvindex(idCounts,0,sno-2),mvindex(idCounts,sno,-1)),mvindex(idCounts,1,-1)) 
| rex field=idCounts "(?&amp;lt;LoginIds&amp;gt;\S+)#(?&amp;lt;logCounts&amp;gt;\S+)" 
| table LoginID Organization Section LoginIds logCounts&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 15:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640855#M222032</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2023-04-20T15:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate variance of a group leaving one ID at a time?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640933#M222078</link>
      <description>&lt;P&gt;|makeresults&lt;BR /&gt;| eval _raw="&lt;BR /&gt;LoginID AccessDate Organization Section logCount&lt;BR /&gt;1 10thApril O1 S1 1.39&lt;BR /&gt;2 11thApril O2 S2 1.76&lt;BR /&gt;3 12thApril O1 S1 2.45&lt;BR /&gt;4 10thApril O1 S1 5.67&lt;BR /&gt;5 11thApril O2 S2 2.34&lt;BR /&gt;6 12thApril O1 S1 1.23&lt;BR /&gt;7 13thApril O2 S2 2.56"&lt;BR /&gt;| multikv forceheader=1&lt;BR /&gt;| stats list(LoginID) list(logCount) stdev(logCount) AS Variance BY Organization Section&lt;BR /&gt;| eval Variance = pow(Variance, 2)&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 00:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-variance-of-a-group-leaving-one-ID-at-a-time/m-p/640933#M222078</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-21T00:21:29Z</dc:date>
    </item>
  </channel>
</rss>

