Splunk Search

How to create a stats table with field values based off of other fields in same stats table?

cmeyers
Explorer

Hello! I am sure my wording is way more complicated than what I want. Basically, the end result being a stats table along the lines of:

Host | AvgLogCount | Min_Total | Max_Total
Router1 |
Router2 |

And then the values filled in from there. The timespan in which I am looking at is 1 week. I was thinking using something along the lines of:

index=db device_type=router | timechart span=1d count | eventstats avg(count) as AvgLogCount, min(count) as Min, max(count) as Max

When I do this, there are X amount of rows that there are days, with the values matching the next row. I get why that is happening, but I want to turn it into each row listing a different Host, and the rest of the columns' value be of the respective host. Do I need something along the lines of:

 index=db device_type=router | timechart span=1d count | eventstats avg(count) as AvgLogCount by host, min(count) as Min by host, max(count) as Max by host

I think that is on the right track, but it doesn't return anything. Any help would be greatly appreciated! And hopefully my wording makes sense.

Thank you!

Tags (1)
0 Karma

woodcock
Esteemed Legend

Like this:

index=db device_type=router | timechart span=1d count by host | stats avg(count) AvgLogCount min(count) AS Min_Total max(count) AS Max_Total | rename host AS Host
0 Karma

somesoni2
Revered Legend

If you're looking for per week stats (like avg log count per week, min/max by week), then try something like this

 index=db device_type=router | bucket span=1w _time | stats count  by _time host | stats avg(count) as AvgLogCount min(count) as Min max(count) as Max by host
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...