Splunk Search

## Bell curve from stats

Explorer

I haven't seen much on creating a bell curve in Splunk. I've created a query that returns 30,000 events for 40+ associates over a month. Each event contains the number of minutes they've worked a specific activity. I then use stats to sum the time each associate works:

``````stats sum(hoursWorked) by Associate
``````

but I want to use bins to create a bell curve to show the "normal" distribution of each associate's work. I have tried several ways with no success. I'm basically trying to show the number of associates that fall into each bin of number of hours worked.

I want it to be something like:

``````bin span=5 hoursWorked |
stats count(sum(hoursWorked) by Associate) by hoursWorked
``````

but I realize I'm trying to count a table there. Help?

Tags (4)
1 Solution
SplunkTrust

If you want to chart the distribution of monthly sums, you can do this:

``````stats sum(hoursWorked) as hours by Associate
| bin span=5 hours
| stats count by hours
``````

That will give you a chart with the number of Associates per five-hour spans of monthly work.

SplunkTrust

If you want to chart the distribution of monthly sums, you can do this:

``````stats sum(hoursWorked) as hours by Associate
| bin span=5 hours
| stats count by hours
``````

That will give you a chart with the number of Associates per five-hour spans of monthly work.

SplunkTrust

You can add a `| sort hours`, which should use a more natural sorting order than `stats`.

Explorer

Thank you ... this worked fairly well, but for one small problem. The bins are treated as strings, which means that, when graphed, it shows the bin "5-10" (hours) after the bin "25-30"

And this is exacerbated if I make the bins for 1 hour spreads.

Any idea how I can fix that?

Explorer

Got it. Removed the bins, then did chart count span={}

Get Updates on the Splunk Community!

#### Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

#### Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

#### Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...