Getting Data In

Working with CSV

reverse
Contributor

I have CSV like this-

    PPAGE_ID1   PPAGE_ID2   PPAGE_ID3   PPAGE_ID4   PPAGE_ID5   PPAGE_ID6   
1-Jan   123 123 123 123 123 123 
2-Jan   456 456 456 456 456 456 
3-Jan   789 789 789 789 789 789 
4-Jan   98  98  98  98  98  98  
5-Jan   87587   87587   87587   87587   87587   87587   

how can I take average by PPAGE_ID6 or PPAGE_ID100 ?
Please help.

Tags (2)
0 Karma
1 Solution

to4kawa
Ultra Champion
| makeresults
| eval _raw="Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
1-Jan,123,123,123,123,123,123
2-Jan,456,456,456,456,456,456
3-Jan,789,789,789,789,789,789
4-Jan,98,98,98,98,98,98
5-Jan,87587,87587,87587,87587,87587,87587"
| multikv forceheader=1
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
`comment("this is your sample")`
`comment("from here, the logic")`
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
| untable Date PPAGE count
| eventstats avg(count) as average by PPAGE

Hi, folks. how about this.

View solution in original post

to4kawa
Ultra Champion
| makeresults
| eval _raw="Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
1-Jan,123,123,123,123,123,123
2-Jan,456,456,456,456,456,456
3-Jan,789,789,789,789,789,789
4-Jan,98,98,98,98,98,98
5-Jan,87587,87587,87587,87587,87587,87587"
| multikv forceheader=1
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
`comment("this is your sample")`
`comment("from here, the logic")`
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
| untable Date PPAGE count
| eventstats avg(count) as average by PPAGE

Hi, folks. how about this.

reverse
Contributor

amazing! you are awesome!.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is not CSV as there are no commas. Furthermore, the number of header fields is not the same as the number of fields in each row so Splunk will not ingest it properly. Can you change how the file is created?

---
If this reply helps you, Karma would be appreciated.

reverse
Contributor

lets assume that is a proper CSV with header as page id .. 1st column as date and rows as values against that date

0 Karma

reverse
Contributor

@jnudell_2 @Vijeta please help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...