avg() (aggregation function)
Calculates the average (arithmetic mean) of Expr across the group.
- Can only be used in context of aggregation inside summarize
- Expr: Expression that will be used for aggregation calculation. Records with
nullvalues are ignored and not included in the calculation.
The average value of Expr across the group.
The following example caluculates the average severity value of the system.
events | poject severity | summarize avg(severity)