Splunk Search

How to compare average of last 30 days to last 90 days in single search?


I believe there is no report Splunk cannot produce, but I'm having trouble with this one. I'd like to generate a report that compares the last 30 days average duration with last 90 days average duration and shows the increase/decrease. I am having no troubles getting the last 90 day average, but I can't figure out how to include the last 30 day average in the same query... The data I'm working with is similar to this

date Job Duration
9/1/2022 Job1    33
9/1/2022 Job2   12
9/1/2022 Job3   128
9/2/2022 Job1   14
9/2/2022 Job2   99
9/2/2022 Job3   128
9/3/2022 Job1   16
9/3/2022 Job2   33
9/3/2022 Job3   22
9/4/2022 Job1  196
9/4/2022 Job2  393
9/4/2022 Job3 192

I'd like a report that looks like this.
 Job          All  Days    Last 2 Days
Job1        21                17
Job2       44                 35
Job3       28                 17

I can generate the ALL Days, but am not sure how to get the last 2 days.. Heres what I have.

| bucket=_time span=1d
| stats sum(duration) as duration by time, jobtype
| stats avg(duration) as duration by jobtype

Any gurus out there that can help? 


Labels (1)
0 Karma


eventstats doesn't support window parameter as far as I'm aware.  I've tried the streamstats parameter,  which does have a windows and start_window parameter, but can't seem to get it to provide the data I'm after

0 Karma


Have you try eventstats with window parameter?

0 Karma


eventstats doesn't support the window parameter.  I tried streamstats with window and time_window, but I can't seem to get it to report correctly

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...