Splunk Search

Calculate time avg time and std deviation between log entries

tradecraft1914
Explorer

I am trying to average calculate the time between web log entries. If an IP on the network visits the same URL multiple times in a given time period we want to calculate the average time between visits. I cant really do a transaction (at least I dont think so) because the events are the same..no begin or end.

I have a search that groups the IP's that visit a URL more than once and also grabs the log entries for each time the URL is visited.

The fields in the output are:

Timestamp, Src_IP, URL, Count

Now for the fun part. Once average time is calculated we want to calculate standard deviation.

Any help would be greatly appreciated!

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

Use streamstats

   sourcetype=myweblog 
   | streamstats window=1 global=f current=f
       last(Timestamp) as next_ts
     by Src_IP,URL
   | eval tm_to_next=next_ts-Timestamp
   | stats 
       avg(tm_to_next)
       stdev(tm_to_next)
     by Src_IP,URL 
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...