Hi,
I have a log trace like, ...........................wages: 50
I have written a splunk query to skip all the entries before "wages:" and print only the values like 50, 30, whatever.
sourcetype=mysource host=myhost* "myClassName" | rex field=_raw "(?<"ac">(?<=wages:).*?$)" | stats count by ac
Now, I'm not able to find the median/ average of the values in ac.
Eg: (50+50)/2
Can you please help me in obtaining this value.
Thanks
you can do |stats avg(ac)
No it dint work 😞
It is displaying nothing
Did you check if you are getting any values in ac, just see what below gives you
sourcetype=mysource host=myhost* "myClassName" | rex field=_raw "(?<"ac">(?<=wages:).*?$)" | table ac
Yes, the query sourcetype=mysource host=myhost* "myClassName" | rex field=_raw "(?<"ac">(?<=wages:).*?$)" | table ac , returns me some values, like, 30, 50, etc.,
but when i give stats avg(ac), it doesn't return any result
sourcetype=mysource host=myhost* "myClassName" | rex field=_raw "(?<"ac">(?<=wages:).*?$)" | stats avg(ac)