Splunk Search

Using stats result of a field in one sourcetype to compute a values for a field in another sourcetype.

thirumalreddyb
Communicator

There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_travelled), stdev(hours_travelled) and use them both values to compute Normal distribution on a scale, where scale has multiple values ranging from 1.0 to 10.0 with an increment in 0.01. I have to compute values for (Scale-mean)/stdev

0 Karma
1 Solution

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

View solution in original post

0 Karma

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

I am sorry but I am not clear on what is the second source type?

Sometimes it helps if you give an example of the data and the output you would like.

0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...