Splunk Search

Using stats result of a field in one sourcetype to compute a values for a field in another sourcetype.

Communicator

There are two sourcetypes, The first sourcetype has a field called hours_travelled. Now I have to compute mean(hours_travelled), stdev(hours_travelled) and use them both values to compute Normal distribution on a scale, where scale has multiple values ranging from 1.0 to 10.0 with an increment in 0.01. I have to compute values for (Scale-mean)/stdev

0 Karma
1 Solution

Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

View solution in original post

0 Karma

Communicator

I used eventstats and i'm successful in fetching the data. Thanks to all of you who tried to help.

View solution in original post

0 Karma

Splunk Employee
Splunk Employee

I am sorry but I am not clear on what is the second source type?

Sometimes it helps if you give an example of the data and the output you would like.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!