Hi Community,
i am struggling to understand the AVG Function in AQL.
I use the following query to see how many events arrived in the last 1440 Minutes and the average EPS.
SELECT
LOGSOURCENAME(logsourceid) AS "Log Source",
SUM(eventcount) AS "Number of Events in Interval",
SUM(eventcount) / 86400 AS "EPS in Interval",
AVG(eventcount) as "Average"
FROM
events
GROUP BY
"Log Source"
ORDER BY "EPS in Interval"
DESC LAST 1440 MINUTES
I get as Average 1.0. What does that mean?
Besides..in the AQL-documentation there is
To view the number of average events from a source IP:
select avg(eventCount) from events group by sourceIP
I only see 1.0
Have I slipped up somewhere?
I use AVG for other calculations such as here below and it works fine:
select SUM("Value") AS "Summe", AVG("Value") AS "Mittelwert", "Metric ID", "Hostname"
from events
where LOGSOURCENAME(logsourceid) ILIKE '%%health%%'
group by "Metric ID", "Hostname"
last 2 minutes
Thank you in advance
Regards,
Bruno
------------------------------
Bruno Oliveira
------------------------------