Splunk Dev

How to average all columns in a chart for a group of results?

splunk_user_jk
New Member

Here's what I'm trying to do:

Imagine a search result from Splunk comes back with results:

User | Field 1 | Field 2 | Field 3 | Field 4


A | 1 | 0 | 1 | 2
B | 3 | 0 | 1 | 1
C | 0 | 0 | 0 | 0

Desired Result:
A chart

Field 1 | Field 2 | Field 3 | Field 4

1.33 | 0 | .666 | 1

So the goal is to get the average User's value for each field.

Tags (1)
0 Karma

Vijeta
Influencer

You could do it

index=<index name>| stats avg(Field1) as Field1, avg(Field2) as Field2, avg(Field3) as Field3, avg(Field4) as Field4
0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...