Splunk Search

## Stats with different bins (full time period AND 5 min intervals)- How to compare average time?

Path Finder

I have a need to compare the average time for certain events with the 5 min bucket/bins of the same events. The idea is to find 5 min intervals that deviate more than a certain percentage from the average response times and then in some way display those intervals.

I am however struggling to figure out how to output the Average for the entire time period but also calculate the 5 minute intervals.

The following query, returns nothing (can you even do 2 Stats in the same query?):

search | stats avg(Value) as AvgEntirePeriod | bin _time span=5m | stats avg(Value) by _time

Any ideas on how to write this?

Labels (1)
• ### stats

Tags (2)
1 Solution
SplunkTrust

Hi @dmoberg,

you can use eventstats to have the average of the full period, something like this:

``````search
| eventstats avg(Value) as AvgEntirePeriod
| bin _time span=5m
| stats
avg(Value) AS AvgFiveMinutes
values(AvgEntirePeriod) AS AvgEntirePeriod
BY _time
| eval perc=round(AvgFiveMinutes/AvgEntirePeriod*100,2)``````

Ciao.

giuseppe

Communicator

You can do as many stats calls as you like in a query, but what you need is eventstats. Also timechart can be used to replace the bin and stats.

search | timechart span=5m avg(Value) as binAvg | eventstats avg(binAvg) as allAvg

SplunkTrust

Hi @dmoberg,

you can use eventstats to have the average of the full period, something like this:

``````search
| eventstats avg(Value) as AvgEntirePeriod
| bin _time span=5m
| stats
avg(Value) AS AvgFiveMinutes
values(AvgEntirePeriod) AS AvgEntirePeriod
BY _time
| eval perc=round(AvgFiveMinutes/AvgEntirePeriod*100,2)``````

Ciao.

giuseppe

Path Finder

Thanks! The EventStats did the trick

SplunkTrust

Hi @dmoberg,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

Get Updates on the Splunk Community!

#### .conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

#### Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

#### Troubleshooting the OpenTelemetry Collector

In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...