Splunk Search

How to add a column of averages to a timechart?

Engager

Similar to how timechart sum() by ip | addtotals which adds a "Totals" Column to a timechart, how can you add an averages column?

0 Karma

Revered Legend

I don't think there is a native way to get that. Try this workaround

... timechart sum(..) by ip | eval count=0 | foreach * [eval count=count+1] | addtotals | eval Average=Totals/count
0 Karma

Engager

This worked perfect for me

0 Karma