Splunk Search

stats option compatibility

VI371887
Path Finder

Does stats support function inside function like shown below ?

Where first i want to take percentile90 of PERCENT90 field value and then sum it up by function as shown below in query

 search........... | eval PERCENT90=round(PERCENT90,2)  |  eval DAY=strftime(_time, "%d-%m-%Y:%H:%M:%S")    |  stats DC(DAY) as DayCount **sum(Perc90(PERCENT90))**  by FUNCTION

I am trying to get the below result

search........ | rex field=source "APP_(?.*)"  | eval PERCENT90=round(PERCENT90,2)  |  eval DAY=strftime(_time, "%d-%m-%Y:%H:%M:%S")    | stats **Perc90**(PERCENT90) as **record** |   stats DC(DAY) as DayCount **sum(record)** as SUMA by FUNCTION

so I want to pass the percentile90 calculation done from first stats to next stats sum()

0 Karma

wenthold
Communicator

try changing | stats perc90(PERCENT90) to | eventstats perc90(PERCENT90)

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...