Splunk Search

How to achieve difference between rate_sum and rate_avg aggregations using mstats command?

tankelvi
New Member

Hi,

I am trying to create a timechart using mstats command but I have some questions as follows, I would appreciate it if I am able to get some answers or clarifications on them:

  1. What is the difference between the aggregations which are rate_avg() and rate_sum() when using mstats command?
  2. We observed that no matter which aggregations we are using, the graphs are returning the same result. Example are as follows:
    1. Using rate_avg
      tankelvi_3-1681985404673.png
    2. Using rate_sum
      tankelvi_2-1681985344887.png

Thank you very much.

 

Best Regards,

Kelvin.

 

@ericaooi 

Labels (1)
0 Karma

gcasaldi
Explorer

Hi,
have you tried to see if it depends on the: 
| timechart sum
command?

bye

G.

0 Karma

tankelvi
New Member

Hi,

Thanks for the reply. I tried to do the queries in different sets of combinations and the results are as shown in the figure below:

tankelvi_0-1683013566244.png

Based on the result:

1) rate_sum & timechart sum(), rate_avg & timechart sum(), rate_sum & timechart per_minute(), rate_avg & timechart per_minute() all have the same result value.

2) rate_sum & timechart avg(), rate_avg & timechart avg() have the same result value.

3) If solely based on this observation, it seems like there is no difference on whether to use rate_sum or rate_avg to construct the graph

or is there anything that I miss or did wrongly? Any suggestion on how to construct the query to be able to fully utilize the rate_sum and rate_avg under different scenario?

Thanks a lot in advance.

Best Regards,

Kelvin.

 

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...