Splunk Search

Using stats result of a field in one sourcetype to compute a values for a field in another sourcetype.

thirumalreddyb
Communicator

There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_travelled), stdev(hours_travelled) and use them both values to compute Normal distribution on a scale, where scale has multiple values ranging from 1.0 to 10.0 with an increment in 0.01. I have to compute values for (Scale-mean)/stdev

0 Karma
1 Solution

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

View solution in original post

0 Karma

thirumalreddyb
Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

I am sorry but I am not clear on what is the second source type?

Sometimes it helps if you give an example of the data and the output you would like.

0 Karma
Get Updates on the Splunk Community!

Cloud Platform | Customer Change Announcement: Email Notification Will Be Available ...

The Notification Team is migrating our email service provider since currently there’s no support ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...