Syntax:
windowstats field=<field> window="<string>" style="<string>" rename="<string>" function="<string>"
Required arguments:
field=<field>
Description: field name
Optional arguments:
window="<string>"
descirption: winow size
default=10
style="<string>"
description: define how the winow is moving. three avialable options (group, dynamic or gradual)
default= group
rename="<string>"
description: the result field name
default: windowstats_result_<current_time>
function="<string>"
description: function performed to the window. the following are avilable functions:
-"avg": calculate the average
-"stdev": calculate the standard deviation
-"max": return the maximum value in the window
-"min": return the minimum value in the window
-"median": return the middle value in the window after sorting it.
-"values": return the unique values in the window
-"sum": calculate the summation
-"list": list all values in the window
-"dc": calculate the unique values in the window
-"mode": return the most frequent value in the window
-"number": labeling the window element starting from 1,2,3,...
default= "avg"
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.