Splunk Search

How can a row of average hourly event volume be appended to a chart with Fridays' hourly totals and added totals?


Here is my attempt at creating a chart of hourly counts for previous Fridays. I have added row and column totals, but can't quite figure out how to add hourly averages per day.

index=everything earliest=-2week@week datewday="friday"
| eval date = strftime(
time, "%Y-%m-%d")
| eval datehour = strftime(time, "%H")
| chart count by datehour date useother=f usenull=f
| addtotals col=t labelfield=date
hour label="Total"
| appendpipe [ | stats avg(count) as date by datehour
| eval date
hour = "Average" ]


