I need to calculate average time take to resolve different incidents in splunk. If anybody have query for same??
In the end, I have created a solution for it myself. https://splunkbase.splunk.com/app/4591/
I have the same requirement.
I need to calculate the average time for all the notables to get resolved over a 30 day period.
Can anyone help me with the splunk query regarding same?
I couldn't get the question properly. Could you please explain in precise.
We have different notable search and have alerts to trigger for same. I need to have query which shows when incident status changes to "in progress" and when to "resolve" and average ( consider for monthly ) time taken to resolve it.