All Apps and Add-ons

How does the moving average work?

rosho
Communicator

Hi

How does the "moving average work"?
With "trendline" I am computing 5 and 10 events. But with "streamstats" I am computing the statistics of only 5 events.

I do not understand.

This is the SPL from the MLTK.

| inputlookup cyclical_business_process.csv
| trendline sma5(logons) as sma5_logons ema10(logons) as ema10_logons
| eval this_date_day = strftime(_time, "%w")
| eval this_date_hour = strftime(_time, "%H")
| eval this_date_day = strftime(_time, "%w")
| eval this_date_day = this_date_day."_"
| eval this_date_hour = this_date_hour."_"
| reverse
| streamstats current=f window=5 first(logons) as LogonsFromTheFuture
| reverse
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...