The **streamstats** command calculates summary statistics in a rolling, cumulative window across your events.
It evaluates row-by-row in the order the events currently exist. You can use the `window` argument to calculate running averages of the last N events.
index=cpu | streamstats window=5 avg(cpu_usage) as rolling_cpu_avg