Splunk Search

How to get average value of fields?

sekhar463
Path Finder

hi all,

i have some events with a field called RUNTIME for each job.

how can i get the average value of RUNTIME for each of the job and result will be on new field

 

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

I assume "results will be new field" means that you want the average along with raw events.  In this case, eventstats is your friend.

| eventstats avg(RUNTIME) AS RUNTIME_avg BY JOID

 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463 ,

pease try something like this:

<your_search>
| stats avg(RUNTIME) AS RUNTIME_avg BY JOID

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats avg(RUNTIME) as average_runtime
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...