Splunk Search

Cumulative hourly Average

Rukmani_Splunk
Path Finder

Hi All,
I have counts of some offers for every hour eg 9-10 30 and then 10-11 - it is 40
it should be cumulative one. For example
00- 20
01-(20+10)=30
02-(30+20)=50 . But it will not be accumulated in the data. It will be just
00-20
01-10
02-20
Now i have 15 days data. like this
30 th March 00- 20, 01-10,02,-20
31st March 00-10,01-15,02-15
1st April 00-10,01-20,02-15

Now firsrt dat a should be changed like thi s through splunk
30 th March 00- 20, 01-30,02,-50
31st March 00-10,01-25,02-40
1st April 00-10,01-30,02-45

Then i have to take median or average by hours.

Please help

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...