Splunk Enterprise

How to Build Average of Last 4 Monday(Current day) vs Today in a Timechart for HTTPS_CODE ?

tonishantsms
Observer

Hey @carasso and @splunk team

I want to build the splunk query using the below requirements:

  • Data Source: sourcetypepcf app_name=xyz HTTP_PATH="/*"
  • Time Frame: The query should cover a 4-week period (earliest=-4w).
  • Display: Calculate and display the average count per hour for the current day of the week for HTTP_STATUS_CODE. 

Using the reference #https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-Chart-Average-of-Last-4-Thursdays-vs-Tod....

We build the query but while we calculate the average we are getting zero results.

Query is - [search ] earliest=-4w | eval current_day = strftime(now(), "%A") | eval log_day = strftime(_time, "%A") | where current_day == log_day | timechart span=1h avg(count) by HTTP_STATUS_CODE.

I would except to take the average by hour for all 4 days and build the timechart span by 1hours for 24 hours.

 

Can you please for the same...

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

[search ] earliest=-4w 
| eval current_day = strftime(now(), "%A") 
| eval log_day = strftime(_time, "%A") 
| where current_day == log_day
| eval hour=strftime(_time, "%H")
| eval day=strftime(_time, "%d")
| stats count by hour day HTTP_STATUS_CODE 
| chart avg(count) as average by hour HTTP_STATUS_CODE
0 Karma
Get Updates on the Splunk Community!

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...