I know that the dc(USERNAME) for the 12:00 date_hour for 10/1/2016 is 2 and that the dc(USERNAME) for the 12:00 date_hour for 10/2/2016 is 1. I'd like to be able to have Splunk give me the average of those days worth of date_hours (i.e. 1.5)
I've tried several different iterations of the below without any success.
sourcetype=usage | timechart span=1h dc(USERNAME) as user_count | stats avg(user_count) by date_hour | sort date_hour
My original attempt included the below, which also doesn't produce results.
sourcetype=usage | stats avg(dc(USERNAME)) by date_hour | sort date_hour