<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create total average/median/max of field in a separate table? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665945#M228468</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I tried the command you suggested and it did not show any effects&lt;BR /&gt;Please suggest.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 00:11:44 GMT</pubDate>
    <dc:creator>LearningGuy</dc:creator>
    <dc:date>2023-10-24T00:11:44Z</dc:date>
    <item>
      <title>How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665858#M228457</link>
      <description>&lt;P&gt;&lt;BR /&gt;How to create total average/median/max of field in a separate table?&lt;BR /&gt;Thank you in advance&lt;BR /&gt;&lt;BR /&gt;| index=testindex&lt;BR /&gt;| table company, ip, Vulnerability, Score&lt;/P&gt;&lt;TABLE width="434"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="83"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="150"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;STRONG&gt;Vulnerability&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="91"&gt;&lt;STRONG&gt;Score&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip1&lt;/TD&gt;&lt;TD&gt;Vuln1&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip1&lt;/TD&gt;&lt;TD&gt;Vuln2&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip2&lt;/TD&gt;&lt;TD&gt;Vuln3&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip2&lt;/TD&gt;&lt;TD&gt;Vuln4&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip3&lt;/TD&gt;&lt;TD&gt;Vuln5&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip3&lt;/TD&gt;&lt;TD&gt;Vuln6&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Group by IP&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;=&amp;gt; This worked just fine&lt;BR /&gt;| stats values(company), avg(Score) as AvgScore by ip&lt;/P&gt;&lt;TABLE width="343"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="83"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="150"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;STRONG&gt;AvgScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip1&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip2&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CompanyA&lt;/TD&gt;&lt;TD&gt;ip3&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Group by Company&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;=&amp;gt;&amp;nbsp; how do I &lt;U&gt;&lt;STRONG&gt;group by company&lt;/STRONG&gt;&lt;/U&gt; after &lt;U&gt;&lt;STRONG&gt;group by ip&lt;/STRONG&gt;&amp;nbsp;(using stats)&amp;nbsp;&lt;/U&gt;and put it on a separate table?&lt;BR /&gt;| stats avg(AvgScore) as Average, avgAvgScore) as Median, max( AvgScore) as Max by company&lt;/P&gt;&lt;TABLE width="434"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;&lt;STRONG&gt;Company&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="147.578px" height="25px"&gt;&lt;STRONG&gt;Average&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="107.234px" height="25px"&gt;&lt;STRONG&gt;Median&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="88.0312px" height="25px"&gt;&lt;STRONG&gt;Max&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;CompanyA&lt;/TD&gt;&lt;TD width="147.578px" height="25px"&gt;2.7&lt;/TD&gt;&lt;TD width="107.234px" height="25px"&gt;3&lt;/TD&gt;&lt;TD width="88.0312px" height="25px"&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 23 Oct 2023 14:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665858#M228457</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-23T14:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665866#M228461</link>
      <description>&lt;P&gt;A separate table requires a separate search.&lt;/P&gt;&lt;P&gt;If this is in a dashboard then consider making the first table a base search and the second table a post-processing of the first.&amp;nbsp; That will save you time and resources when the dashboard runs.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
&amp;lt;search id="base"&amp;gt; &amp;lt;!-- "base" can be any string --&amp;gt;
  &amp;lt;query&amp;gt;| index=testindex
| table company, ip, Vulnerability, Score
| stats values(company), avg(Score) as AvgScore by ip&amp;lt;/query&amp;gt;
...
&amp;lt;/search&amp;gt;
...
&amp;lt;search base="base"&amp;gt; &amp;lt;!-- Use the same string as above --&amp;gt;
&amp;lt;query&amp;gt;| stats avg(AvgScore) as Average, avgAvgScore) as Median, max( AvgScore) as Max by company&amp;lt;/query&amp;gt;
&amp;lt;/search&amp;gt;
...&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 23 Oct 2023 15:03:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665866#M228461</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-23T15:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665903#M228465</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I tried your suggestion and it worked fine. I am accepting this as a solution&lt;BR /&gt;Can you also suggest how to put the average, median and max on the bottom of the table?&lt;BR /&gt;Thank you again&lt;BR /&gt;Below is the example:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="343"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;&lt;STRONG&gt;company&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;&lt;STRONG&gt;ip&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;&lt;STRONG&gt;AvgScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;CompanyA&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;ip1&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;CompanyA&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;ip2&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;CompanyA&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;ip3&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;Average&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;2.7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;Median&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90.1562px" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="143.906px" height="25px"&gt;Max&lt;/TD&gt;&lt;TD width="107.938px" height="25px"&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 18:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665903#M228465</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-23T18:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665917#M228466</link>
      <description>&lt;P&gt;I think you can do that with the &lt;FONT face="courier new,courier"&gt;appendpipe&lt;/FONT&gt; command, which processes the current results and adds new results to bottom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(company), avg(Score) as AvgScore by ip
| appendpipe [ stats avg(AvgScore) as Average, median(AvgScore) as Median, max(AvgScore) as Max by company ]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 00:24:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665917#M228466</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-24T00:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665945#M228468</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I tried the command you suggested and it did not show any effects&lt;BR /&gt;Please suggest.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 00:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665945#M228468</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-24T00:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665946#M228469</link>
      <description>&lt;P&gt;I used the wrong case in the field name.&amp;nbsp; Try my edited answer.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 00:24:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665946#M228469</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-10-24T00:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to create total average/median/max of field in a separate table?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665948#M228470</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;There would be no difference because I converted your suggestion to my real data, so I already fixed any details&lt;BR /&gt;Please suggest.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Marius&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 01:31:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-total-average-median-max-of-field-in-a-separate/m-p/665948#M228470</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-24T01:31:42Z</dc:date>
    </item>
  </channel>
</rss>

