Splunk Search

How to create graph based on Std deviation & Avg

jaibalaraman
Path Finder

Hi 

Can anyoine suggest me how to create Avg & Std Dev graph from the fields

 

jaibalaraman_0-1712025787892.png

 

Tags (1)
0 Karma

jaibalaraman
Path Finder

Hi Kendall 

yes i tried that, stil not getting any output 

jaibalaraman_0-1712027466637.png

 

0 Karma

KendallW
Contributor

Add a space between  the two timechart functions. E.g. 

| timechart avg(event.Properties.duration) stdev(event.Properties.duration)

Also, you can remove the 

| iplocation

 as we aren't using any of the fields that command adds for this visualization, so it will only slow down the search.

0 Karma

tscroggins
Champion

Hi @jaibalaraman,

You can calculate the mean and standard deviation using the stats command:

| stats avg(event.Properties.duration) as u stdev(event.Properties.duration) as s

however, that won't produce a chart.

At a glance, your data is not normally distributed. You can generate a simple histogram with the chart command:

| chart count over event.Properties.duration span=31

If you have Splunk Machine Learning Toolkit installed, you can use the histogram macro and visualization:

| `histogram("event.Properties.duration", 31)`

Note that the histogram macro uses the bin command:

bin "$var$" bins=$bins$ | stats count by "$var$" | makecontinuous "$var$" | fillnull count

It won't necessarily honor your bin count.

What type of graph or visualization would you like to create?

0 Karma

jaibalaraman
Path Finder

The below 2 commands are not working 

| `histogram("event.Properties.duration", 31)`

bin "$var$" bins=$bins$ | stats count by "$var$" | makecontinuous "$var$" | fillnull count

 

What type of graph or visualization would you like to create?

Just want to create a dashboard tile to show the metric 

0 Karma

KendallW
Contributor

Hi @jaibalaraman try this

. . . | timechart avg(event.Properties.duration) stdev(event.Properties.duration)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...