Here's what I'm trying to do:
Imagine a search result from Splunk comes back with results:
User | Field 1 | Field 2 | Field 3 | Field 4
A | 1 | 0 | 1 | 2
B | 3 | 0 | 1 | 1
C | 0 | 0 | 0 | 0
Desired Result:
A chart
1.33 | 0 | .666 | 1
So the goal is to get the average User's value for each field.
You could do it
index=<index name>| stats avg(Field1) as Field1, avg(Field2) as Field2, avg(Field3) as Field3, avg(Field4) as Field4