Splunk Search

What is the biggest difference between perc<>() and using predict?

aohls
Contributor

I have used predict before and now am seeing perc, which I haven't used as much. What is the largest difference between these two? Is one favored over the other or are they different?

Labels (1)
1 Solution

bowesmana
SplunkTrust
SplunkTrust

@aohls They are different beasts. predict is about forecasting, but perc is about calculating percentiles, e.g.

perc50(x) is the same as the median.

perc90(x) is the 90th percentile.

perc is used in aggregation commands, such as *stats, timechart.

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

@aohls They are different beasts. predict is about forecasting, but perc is about calculating percentiles, e.g.

perc50(x) is the same as the median.

perc90(x) is the 90th percentile.

perc is used in aggregation commands, such as *stats, timechart.

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...