Splunk Search

How to create graph based on Std deviation & Avg

jaibalaraman
Path Finder

Hi 

Can anyoine suggest me how to create Avg & Std Dev graph from the fields

 

jaibalaraman_0-1712025787892.png

 

Tags (1)
0 Karma

jaibalaraman
Path Finder

Hi Kendall 

yes i tried that, stil not getting any output 

jaibalaraman_0-1712027466637.png

 

0 Karma

KendallW
Contributor

Add a space between  the two timechart functions. E.g. 

| timechart avg(event.Properties.duration) stdev(event.Properties.duration)

Also, you can remove the 

| iplocation

 as we aren't using any of the fields that command adds for this visualization, so it will only slow down the search.

0 Karma

tscroggins
Influencer

Hi @jaibalaraman,

You can calculate the mean and standard deviation using the stats command:

| stats avg(event.Properties.duration) as u stdev(event.Properties.duration) as s

however, that won't produce a chart.

At a glance, your data is not normally distributed. You can generate a simple histogram with the chart command:

| chart count over event.Properties.duration span=31

If you have Splunk Machine Learning Toolkit installed, you can use the histogram macro and visualization:

| `histogram("event.Properties.duration", 31)`

Note that the histogram macro uses the bin command:

bin "$var$" bins=$bins$ | stats count by "$var$" | makecontinuous "$var$" | fillnull count

It won't necessarily honor your bin count.

What type of graph or visualization would you like to create?

0 Karma

jaibalaraman
Path Finder

The below 2 commands are not working 

| `histogram("event.Properties.duration", 31)`

bin "$var$" bins=$bins$ | stats count by "$var$" | makecontinuous "$var$" | fillnull count

 

What type of graph or visualization would you like to create?

Just want to create a dashboard tile to show the metric 

0 Karma

KendallW
Contributor

Hi @jaibalaraman try this

. . . | timechart avg(event.Properties.duration) stdev(event.Properties.duration)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...