Splunk Search

average count events

Shark2112
Communicator

Hey guys.

I need to know what ip have less events then avarage of all devices.

for example:
ip events
1.1.1.1 11
2.2.2.2 10
3.3.3.3 9
4.4.4.4 1

so average is 7.75 and i want to find ip 4.4.4.4

Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

Eventstats is your friend. Assuming your fields are named IP and events:

| eventstats avg(events) as avg_events
| where events < avg_events

View solution in original post

javiergn
Super Champion

Eventstats is your friend. Assuming your fields are named IP and events:

| eventstats avg(events) as avg_events
| where events < avg_events
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...