Splunk Search

AVG Count of a error message

123michi19
Explorer

Good morning,

I log different error messages in SPLUNK and want to get the average number of each error message and create an alert for this.

What I tried:
index="" AND http_message="" | timechart avg(http_message)

Unfortunately it doesn't the deliver the excepted screen.

0 Karma

woodcock
Esteemed Legend

Like this:

index="*" AND http_message="*" 
| timechart count BY http_message
| untable _time http_message count
| stats avg(count) BY http_message
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The avg function requires a numeric field as an argument. Try this query.

index=foo http_message="*"
| stats count by _time, http_message
| timechart avg(count) as avg by http_message
---
If this reply helps you, Karma would be appreciated.
0 Karma

dindu
Contributor

Hi,

Please try the below search and let us whether it worked.

       index="" AND http_message="*" 
       |stats count as tot by http_message,_time
       |stats avg(tot) as Average by _time
0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...