How to compute the mean activity volume per field ...

pavanae

Builder

10-27-2016
12:47 PM

How to Compute the mean activity volume per user in each hour yesterday, and find the ones more than n standard deviations above the mean?

Note: Considering user as a field

Any ideas about writing a search which satisfies the above condition?

1 Solution

vasanthmss

Motivator

10-27-2016
01:52 PM

try something like this,,

base search | timechart span=1h mean(user) as mean, stdev(user) AS std | where std>10 AND mean>10

Re: How to compute the mean activity volume per field in Splunk?

mgrosholz

Path Finder

10-28-2016
04:50 AM

By mean activity, I am assuming you mean the average.

| stats avg(count) by date_hour, user

For standard deviation you can try something like below. Replace "n" with your amount.

| eventstats stdev(count) as deviation | eval outlier=deviation*"n" | where count > outlier