Splunk Search

Using stats result of a field in one sourcetype to compute a values for a field in another sourcetype.

thirumalreddyb
Communicator

There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_travelled), stdev(hours_travelled) and use them both values to compute Normal distribution on a scale, where scale has multiple values ranging from 1.0 to 10.0 with an increment in 0.01. I have to compute values for (Scale-mean)/stdev

0 Karma
1 Solution

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

View solution in original post

0 Karma

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

I am sorry but I am not clear on what is the second source type?

Sometimes it helps if you give an example of the data and the output you would like.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...