Splunk Search

How to achieve difference between rate_sum and rate_avg aggregations using mstats command?

tankelvi
New Member

Hi,

I am trying to create a timechart using mstats command but I have some questions as follows, I would appreciate it if I am able to get some answers or clarifications on them:

  1. What is the difference between the aggregations which are rate_avg() and rate_sum() when using mstats command?
  2. We observed that no matter which aggregations we are using, the graphs are returning the same result. Example are as follows:
    1. Using rate_avg
      tankelvi_3-1681985404673.png
    2. Using rate_sum
      tankelvi_2-1681985344887.png

Thank you very much.

 

Best Regards,

Kelvin.

 

@ericaooi 

Labels (1)
0 Karma

gcasaldi
Explorer

Hi,
have you tried to see if it depends on the: 
| timechart sum
command?

bye

G.

0 Karma

tankelvi
New Member

Hi,

Thanks for the reply. I tried to do the queries in different sets of combinations and the results are as shown in the figure below:

tankelvi_0-1683013566244.png

Based on the result:

1) rate_sum & timechart sum(), rate_avg & timechart sum(), rate_sum & timechart per_minute(), rate_avg & timechart per_minute() all have the same result value.

2) rate_sum & timechart avg(), rate_avg & timechart avg() have the same result value.

3) If solely based on this observation, it seems like there is no difference on whether to use rate_sum or rate_avg to construct the graph

or is there anything that I miss or did wrongly? Any suggestion on how to construct the query to be able to fully utilize the rate_sum and rate_avg under different scenario?

Thanks a lot in advance.

Best Regards,

Kelvin.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...