Splunk Search
Highlighted

How to display the average of each host for a particular search in a timechart?

Builder

I have a search as follows

field_id="X" | eval b=len(_raw) | stats sum(b) as b | eval gb=round(b/1024/1024/1024,2) | eventstats avg(gb) as Avg

Which displays the average gb per each day for that particular search.

Now, how can I make to display average of each host for that particular search in a timechart?

0 Karma
Highlighted

Re: How to display the average of each host for a particular search in a timechart?

Motivator

If host is already a field then


yourBaseSearch
| timechart max(Avg) by host

View solution in original post

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.