<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Calculate Average for multiple fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169766#M48540</link>
    <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search  | addtotals fieldname=intEl intEl* | stats avg(intEl)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 17 Oct 2014 21:38:40 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-10-17T21:38:40Z</dc:date>
    <item>
      <title>Calculate Average for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169765#M48539</link>
      <description>&lt;P&gt;My logs currently capture transaction summaries. The transaction summaries can have 0 to n number of integration.&lt;/P&gt;

&lt;P&gt;For Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2014-10-13T14:05:27 FLAT_TXN_SUMMARY mdUUID=a intId1="ledgerDataSource" intResulstSetCall1="0" intEl1="105" intCnt1="12" intCat1="JDBC" 
2014-10-13T14:05:32 FLAT_TXN_SUMMARY mdUUID=b intId1="dupeCheckCtsDataSource" intResulstSetCall1="0" intEl1="20" intCnt1="1" intCat1="JDBC" intId2="provinqUncommittedDataSource" intResulstSetCall2="17" intEl2="478" intCnt2="33" intCat2="JDBC" intId3="contractDataSource" intResulstSetCall3="2" intEl3="12" intCnt3="1" intCat3="JDBC"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How do I calculate the average of all intEl* when total number of intEl fields is unknown as it will vary per transaction?&lt;/P&gt;

&lt;P&gt;When I search&lt;BR /&gt;
 ....| stats avg(intEl*) &lt;BR /&gt;
I get the average for each intEl field so if I were to use the two log statements above it would give me the average for intEl1, intEl2, and intEl3. I would like one overall average for all intEl*&lt;/P&gt;

&lt;P&gt;...| stats avg(intEl*)&lt;/P&gt;

&lt;P&gt;results: avg(intEl1)= 62.5, avg(intEl2)=478, avg(intEl3)=12&lt;/P&gt;

&lt;P&gt;Would like results to be: AverageintEl=153.75&lt;/P&gt;

&lt;P&gt;Keep in mind there can be an unknown amount of intEl fields.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169765#M48539</guid>
      <dc:creator>Brittany_Carr</dc:creator>
      <dc:date>2020-09-28T17:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate Average for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169766#M48540</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search  | addtotals fieldname=intEl intEl* | stats avg(intEl)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 17 Oct 2014 21:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169766#M48540</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-10-17T21:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate Average for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169767#M48541</link>
      <description>&lt;P&gt;I believe Somesh's answer would actually produce the sum of averages (or an average of sums?) rather than the overall average. Give this a shot:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval field_count = 0 | eval field_sum = 0
    | foreach intEl* [eval field_count = field_count + 1 | eval field_sum = field_sum + '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;']
    | stats sum(field_sum) as field_sum sum(field_count) as field_count
    | eval AverageintEl = field_sum / field_count | fields - field_*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will build a sum and a counter in lock step, giving you the input needed to calculate the average over any number of fields.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2014 22:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169767#M48541</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-17T22:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate Average for multiple fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169768#M48542</link>
      <description>&lt;P&gt;This answer was really close to answering my question. The foreach really helped me out. Here is what ended up working for me&lt;/P&gt;

&lt;P&gt;...| stats count(intEl*) sum(intEl*) &lt;BR /&gt;
| eval intEl_count = 0 &lt;BR /&gt;
| foreach count* [eval intEl_count = intEl_count + '&amp;lt;&amp;gt;'] &lt;BR /&gt;
| eval intEl_sum = 0 &lt;BR /&gt;
| foreach sum* [eval intEl_sum = intEl_sum + '&amp;lt;&amp;gt;'] &lt;BR /&gt;
| eval AverageIntEl = intEl_sum / intEl_count &lt;BR /&gt;
| fields - field_*&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Calculate-Average-for-multiple-fields/m-p/169768#M48542</guid>
      <dc:creator>Brittany_Carr</dc:creator>
      <dc:date>2020-09-28T17:56:58Z</dc:date>
    </item>
  </channel>
</rss>

