Splunk Search

Using stats result of a field in one sourcetype to compute a values for a field in another sourcetype.

thirumalreddyb
Communicator

There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_travelled), stdev(hours_travelled) and use them both values to compute Normal distribution on a scale, where scale has multiple values ranging from 1.0 to 10.0 with an increment in 0.01. I have to compute values for (Scale-mean)/stdev

0 Karma
1 Solution

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

View solution in original post

0 Karma

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

I am sorry but I am not clear on what is the second source type?

Sometimes it helps if you give an example of the data and the output you would like.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...