Hi,
I need to calculate average of response time in seconds for my application.
Query i am using
index="prod*_ping*" source="*splunk-audit.log" "event=SSO" connectionid=*
| stats avg(responsetime) as AvgRespTimeInSec by connectionid
In connectionid i will get the application details
Please let me know whether my query is correct for calculating the average of response time in seconds?
Regards,
Madhusri R
Of course it depends on your data whether it makes sense or not but in general, | stats avg(field) is indeed the way to calculate average of field values.
Thanks @PickleRick
Then the average of my response time is calculating in seconds right?
Regards,
Madhu R
Depends on your source data. If the field itself is measured in seconds then the average of the values in that field will be also in seconds.
Otherwise you might want to use eval to multiply or divide the value to other unit.