I'm interested to know the average hits per minute by distinct source IP address from my web log data for a given time period.
(I'm sure this is REALLY simple but I've yet to figure it out...)
Is the search you are looking for:
... | bucket _time span=1m | stats dc(clientip) as dcip count(clientip) as totalcount by _time | eval avg_hit=(totalcount/dcip) | fields + _time, avg_hit
The above is giving you the count of hits per distinct
src_ip. But I suppose what you want is the count of distinct
src_ip values, which is
... | timechart span=1m distinct_count(src_ip)
So lemme see here matt -- are you looking to reduce this to a single value per time period that is the avg# of per-ip hits? If so, the above search should be easily adjustable to do that. Please advise.