I am a beginner in Splunk queries. I might would be asking for some simple query but I am not able to construct it after searching a lot. Below is my sample event from message field
REPORT RequestId: 288f34e9-5572-4816-d21e-9fcf5965fad0 Duration: 206.64 ms ..
I can get all events matching this criteria, but I want to do average, min and max of value present in duration in millisecond. Any help on this would be appreciated.
| rex "Duration: (?<duration>[\d\.]+) ms"
| stats avg(duration) as avg min(duration) as min max(duration) as max
Thanks @ITWhisperer it worked 🙂
| rex "Duration: (?<duration>[\d\.]+) ms"
| stats avg(duration) as avg min(duration) as min max(duration) as max