Splunk Search

Finding Average of Time Column

michaelsplunk1
Path Finder

How do we find the average of a table column filled with time values?

Labels (1)
Tags (2)
0 Karma

to4kawa
SplunkTrust
SplunkTrust

sample:

index=_internal sourcetype=splunkd*
| timechart span=1h count by sourcetype
| untable _time sourcetype count
| eventstats avg(count) as average by sourcetype

try untable and eventstats after timechart 

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!