You may find a solution similar to one I needed a while back to be helpful – timechart without using timechart
index=ndx sourcetype=srctp correlationId=* service=* earliest=-60m
| eval secs=strftime(_time, "%S")
| stats dc(correlationId) as TPS by secs service
| stats avg(TPS) as avgTPS by service
| chart avg(TPS) as avgTPS by service
from User warren – Stack Overflow https://stackoverflow.com/questions/70245098/splunk-getting-average-tps-for-each-service/70250170#70250170
via IFTTT