Skip to main content
The series_stats function computes comprehensive statistical measures for a numeric dynamic array (series), returning an array with seven elements containing minimum, maximum, average, variance, standard deviation, and the positions of minimum and maximum values. You can use series_stats when you need a complete statistical summary of time-series data in a single operation. This is particularly useful for understanding data distribution, identifying outliers, calculating confidence intervals, or performing comprehensive data quality assessments without running multiple separate aggregations.

For users of other query languages

If you come from other query languages, this section explains how to adjust your existing queries to achieve the same results in APL.
In Splunk SPL, you typically use multiple stats functions to calculate different statistics. In APL, series_stats provides all common statistics in a single operation on array data, returning them as a 7-element array.
In SQL, you calculate multiple aggregate functions separately. In APL, series_stats provides all these statistics in a single function call on array data, returned as a 7-element array.

Usage

Syntax

Parameters

Returns

An array with seven numeric elements in the following order:

Use case examples

In log analysis, you can use series_stats to get a comprehensive statistical summary of request durations for each user, helping identify performance patterns and outliers.Query
Run in PlaygroundOutputThis query calculates comprehensive statistics for each user’s request durations by extracting specific elements from the 7-element stats array.
  • series_stats_dynamic: Returns the same statistics as a dynamic object with named properties instead of an array.
  • series_max: Compares two arrays element-wise and returns the maximum values.
  • series_min: Compares two arrays element-wise and returns the minimum values.
  • avg: Aggregation function for calculating averages across rows.
  • stdev: Aggregation function for standard deviation across rows.