Getting Data In

How to get the standard deviation of the interval between the occurrence of events?

SRF1LO
Engager

I have a server log in splunk and whenever a user login it will store a record with the username and timestamp.

Now I want to calculate the average and standard deviation for the time interval between two consecutive login. Is there a way to do so in splunk? I have more than 5000 users. Earliest and latest do not work as I want to calculate the time interval between each consecutive logins.

Thanks!

0 Karma

woodcock
Esteemed Legend

If you didn't need to do the by user part, you could also consider autoregress and delta.

0 Karma

felipesewaybric
Contributor

As DalJeanis answer, you can use stats avg(deltatime) and stdev(deltatime) by userId.

0 Karma

vidhyaArumalla
Path Finder

One other way of doing this is

base search
| sort 0 userid,_time
| streamstats range(_time) as timedelta window=2 by userid
| eval timedelta =if(timedelta=0,null,timedelta)
| stats avg(timedelta) as avgtimedelta stdev(timedelta) as stdevtimedelta by userid

0 Karma

DalJeanis
SplunkTrust
SplunkTrust
your search that gets the records you are interested in, with _time and userid.

| sort 0 _time userid
| streamstats current=f last(_time) as prevtime by userid
| eval deltatime= _time - prevtime

Now you have the difference in time between each pair of user logins. The first for each userid will be null, because prevtime will have no value. Then this will give you your average and standard deviation.

| stats avg(deltatime) as avgdelta stdev(deltatime) as stdevdelta by userid

Myself, I would probably want to eliminate weekends from consideration, so I might kill any deltatime that was more than, say, 36 hours. However, such data cleaning will depend entirely on your use case; if your users tend to log on every few days, rather than several times a day, you should leave the data as is, or decide for yourself what makes sense.

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...