Splunk Search

stats option compatibility

VI371887
Path Finder

Does stats support function inside function like shown below ?

Where first i want to take percentile90 of PERCENT90 field value and then sum it up by function as shown below in query

 search........... | eval PERCENT90=round(PERCENT90,2)  |  eval DAY=strftime(_time, "%d-%m-%Y:%H:%M:%S")    |  stats DC(DAY) as DayCount **sum(Perc90(PERCENT90))**  by FUNCTION

I am trying to get the below result

search........ | rex field=source "APP_(?.*)"  | eval PERCENT90=round(PERCENT90,2)  |  eval DAY=strftime(_time, "%d-%m-%Y:%H:%M:%S")    | stats **Perc90**(PERCENT90) as **record** |   stats DC(DAY) as DayCount **sum(record)** as SUMA by FUNCTION

so I want to pass the percentile90 calculation done from first stats to next stats sum()

0 Karma

wenthold
Communicator

try changing | stats perc90(PERCENT90) to | eventstats perc90(PERCENT90)

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...