Getting Data In

Working with CSV

reverse
Contributor

I have CSV like this-

    PPAGE_ID1   PPAGE_ID2   PPAGE_ID3   PPAGE_ID4   PPAGE_ID5   PPAGE_ID6   
1-Jan   123 123 123 123 123 123 
2-Jan   456 456 456 456 456 456 
3-Jan   789 789 789 789 789 789 
4-Jan   98  98  98  98  98  98  
5-Jan   87587   87587   87587   87587   87587   87587   

how can I take average by PPAGE_ID6 or PPAGE_ID100 ?
Please help.

Tags (2)
0 Karma
1 Solution

to4kawa
Ultra Champion
| makeresults
| eval _raw="Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
1-Jan,123,123,123,123,123,123
2-Jan,456,456,456,456,456,456
3-Jan,789,789,789,789,789,789
4-Jan,98,98,98,98,98,98
5-Jan,87587,87587,87587,87587,87587,87587"
| multikv forceheader=1
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
`comment("this is your sample")`
`comment("from here, the logic")`
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
| untable Date PPAGE count
| eventstats avg(count) as average by PPAGE

Hi, folks. how about this.

View solution in original post

to4kawa
Ultra Champion
| makeresults
| eval _raw="Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
1-Jan,123,123,123,123,123,123
2-Jan,456,456,456,456,456,456
3-Jan,789,789,789,789,789,789
4-Jan,98,98,98,98,98,98
5-Jan,87587,87587,87587,87587,87587,87587"
| multikv forceheader=1
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
`comment("this is your sample")`
`comment("from here, the logic")`
| table Date,PPAGE_ID1,PPAGE_ID2,PPAGE_ID3,PPAGE_ID4,PPAGE_ID5,PPAGE_ID6
| untable Date PPAGE count
| eventstats avg(count) as average by PPAGE

Hi, folks. how about this.

reverse
Contributor

amazing! you are awesome!.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is not CSV as there are no commas. Furthermore, the number of header fields is not the same as the number of fields in each row so Splunk will not ingest it properly. Can you change how the file is created?

---
If this reply helps you, Karma would be appreciated.

reverse
Contributor

lets assume that is a proper CSV with header as page id .. 1st column as date and rows as values against that date

0 Karma

reverse
Contributor

@jnudell_2 @Vijeta please help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...