Splunk Enterprise

How to find single value based on result in a table?


Hi everyone,

Please help me with this problem.

After doing some search by Splunk, I have results in a table below:

Id Average
1231 130
1234 540
1568 220
7564 116
7894 273


No I need to calculate some values that based on the average in the table.

For ex: result1= average of id 1231 / average of id 7894

result 2 = average of 1568 / average of 1234

How can I do it please?

Thanks in advanced!

Labels (2)
Tags (2)
0 Karma


Try using chart instead of stats

| eval row=1
| chart avg(Average) as Average by row Id

Depending on the search you used to create your table, you may be able to do this a different way

0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...