Hello,
Is it possible to compute an average of the numerical field by dividing it by the mvcount field I am defining?
I have a field foo whose value is numeric. I have another field bar_count whose value is numeric and is the mvcount of a multivalue field.
For each event, I want to chart the average:
... | chart eval(foo/bar_count) as average_tran
You can either:
... | eval f=foo/bar_count | chart first(f) as average_tran
or
... | chart first(eval(foo/bar_count)) as average_tran
You need an aggregator with chart
(in this case, first()
) as it must be told how to resolve the possibility of multiple values.
I do question why you are charting what will come out as a single value here though, but I assume that you're simplifying somewhat and that your real chart
command has a split-by field. Otherwise, you can really just skip the chart
command entirely.
Thank you!! You have helped me several times in the last few days..