Splunk Dev

How to average all columns in a chart for a group of results?

splunk_user_jk
New Member

Here's what I'm trying to do:

Imagine a search result from Splunk comes back with results:

User | Field 1 | Field 2 | Field 3 | Field 4


A | 1 | 0 | 1 | 2
B | 3 | 0 | 1 | 1
C | 0 | 0 | 0 | 0

Desired Result:
A chart

Field 1 | Field 2 | Field 3 | Field 4

1.33 | 0 | .666 | 1

So the goal is to get the average User's value for each field.

Tags (1)
0 Karma

Vijeta
Influencer

You could do it

index=<index name>| stats avg(Field1) as Field1, avg(Field2) as Field2, avg(Field3) as Field3, avg(Field4) as Field4
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...