Splunk Search

How to achieve difference between rate_sum and rate_avg aggregations using mstats command?

tankelvi
New Member

Hi,

I am trying to create a timechart using mstats command but I have some questions as follows, I would appreciate it if I am able to get some answers or clarifications on them:

  1. What is the difference between the aggregations which are rate_avg() and rate_sum() when using mstats command?
  2. We observed that no matter which aggregations we are using, the graphs are returning the same result. Example are as follows:
    1. Using rate_avg
      tankelvi_3-1681985404673.png
    2. Using rate_sum
      tankelvi_2-1681985344887.png

Thank you very much.

 

Best Regards,

Kelvin.

 

@ericaooi 

Labels (1)
0 Karma

gcasaldi
Explorer

Hi,
have you tried to see if it depends on the: 
| timechart sum
command?

bye

G.

0 Karma

tankelvi
New Member

Hi,

Thanks for the reply. I tried to do the queries in different sets of combinations and the results are as shown in the figure below:

tankelvi_0-1683013566244.png

Based on the result:

1) rate_sum & timechart sum(), rate_avg & timechart sum(), rate_sum & timechart per_minute(), rate_avg & timechart per_minute() all have the same result value.

2) rate_sum & timechart avg(), rate_avg & timechart avg() have the same result value.

3) If solely based on this observation, it seems like there is no difference on whether to use rate_sum or rate_avg to construct the graph

or is there anything that I miss or did wrongly? Any suggestion on how to construct the query to be able to fully utilize the rate_sum and rate_avg under different scenario?

Thanks a lot in advance.

Best Regards,

Kelvin.

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...