The **eventstats** command generates summary statistics and adds them as new fields to *every single raw event*, WITHOUT collapsing the rows.
Unlike `stats` (which destroys raw data to just show the summary table), `eventstats` lets you compare an individual row against the overall average.
index=sales | eventstats avg(revenue) as overall_avg | where individual_revenue > overall_avg