Splunk Search

AVG Count of a error message

123michi19
Explorer

Good morning,

I log different error messages in SPLUNK and want to get the average number of each error message and create an alert for this.

What I tried:
index="" AND http_message="" | timechart avg(http_message)

Unfortunately it doesn't the deliver the excepted screen.

0 Karma

woodcock
Esteemed Legend

Like this:

index="*" AND http_message="*" 
| timechart count BY http_message
| untable _time http_message count
| stats avg(count) BY http_message
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The avg function requires a numeric field as an argument. Try this query.

index=foo http_message="*"
| stats count by _time, http_message
| timechart avg(count) as avg by http_message
---
If this reply helps you, Karma would be appreciated.
0 Karma

dindu
Contributor

Hi,

Please try the below search and let us whether it worked.

       index="" AND http_message="*" 
       |stats count as tot by http_message,_time
       |stats avg(tot) as Average by _time
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...