Splunk Search

Different median results: fast-mode vs verbose-mode

HeinzWaescher
Motivator

Hi,

I'm calculating a median. The result is not the same when I change from fast to verbose mode... Is this expected behaviour?

BR

Heinz

Tags (2)

chanmi2
Path Finder

I can't figure out how Splunk calculating median/perc50 either. The result is just a estimated result when there are hundreds of events from your search.

To get the exact median that wont change, I recommend using exactperc50()

AKG1_old1
Builder

Thanks !! its helpful.

0 Karma

woodcock
Esteemed Legend

Post your search; it depends.

0 Karma

HeinzWaescher
Motivator

The search is very simple...

 sourcetype=A action=B tag=C AND (field1>0 OR field2>0) AND NOT field3=xyz | stats median(field4)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...