Hey guys.
I need to know what ip have less events then avarage of all devices.
for example:
ip             events
1.1.1.1        11
2.2.2.2       10
3.3.3.3        9
4.4.4.4         1
so average is 7.75 and i want to find ip 4.4.4.4
 
					
				
		
Eventstats is your friend. Assuming your fields are named IP and events:
| eventstats avg(events) as avg_events
| where events < avg_events
 
					
				
		
Eventstats is your friend. Assuming your fields are named IP and events:
| eventstats avg(events) as avg_events
| where events < avg_events
