I am trying to feed the results of (2) subsearches into and eval search.
| eval Average=data/asstes [stats sum(data) | return $data] [stats count(MAC_Address) | retun $assets]
there may bay a better way to do this... I need to sum of data divded by to total number of unique MAC addresses.
Any help is appreciated.
Can you post some sample data?
try this instead:
| eventstats sum(data) as sum_of_data dc(MAC_Address) as dc_of_MAC_Address
| eval average = sum_of_data / dc_of_MAC_Address