Splunk Search

How to achieve difference between rate_sum and rate_avg aggregations using mstats command?

tankelvi
New Member

Hi,

I am trying to create a timechart using mstats command but I have some questions as follows, I would appreciate it if I am able to get some answers or clarifications on them:

  1. What is the difference between the aggregations which are rate_avg() and rate_sum() when using mstats command?
  2. We observed that no matter which aggregations we are using, the graphs are returning the same result. Example are as follows:
    1. Using rate_avg
      tankelvi_3-1681985404673.png
    2. Using rate_sum
      tankelvi_2-1681985344887.png

Thank you very much.

 

Best Regards,

Kelvin.

 

@ericaooi 

Labels (1)
0 Karma

gcasaldi
Explorer

Hi,
have you tried to see if it depends on the: 
| timechart sum
command?

bye

G.

0 Karma

tankelvi
New Member

Hi,

Thanks for the reply. I tried to do the queries in different sets of combinations and the results are as shown in the figure below:

tankelvi_0-1683013566244.png

Based on the result:

1) rate_sum & timechart sum(), rate_avg & timechart sum(), rate_sum & timechart per_minute(), rate_avg & timechart per_minute() all have the same result value.

2) rate_sum & timechart avg(), rate_avg & timechart avg() have the same result value.

3) If solely based on this observation, it seems like there is no difference on whether to use rate_sum or rate_avg to construct the graph

or is there anything that I miss or did wrongly? Any suggestion on how to construct the query to be able to fully utilize the rate_sum and rate_avg under different scenario?

Thanks a lot in advance.

Best Regards,

Kelvin.

 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...