<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: latest in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516189#M145033</link>
    <description>&lt;P&gt;could any please help me to find the solution.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2020 05:25:06 GMT</pubDate>
    <dc:creator>vinod0313</dc:creator>
    <dc:date>2020-08-26T05:25:06Z</dc:date>
    <item>
      <title>latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516084#M144956</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I have below logs in last 60 mins&lt;BR /&gt;&lt;BR /&gt;log1: ABC=1,DEF=2,GHI=3&lt;BR /&gt;&lt;BR /&gt;log2:ABC=0,DEF=0,GHI=3&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;while executing my query for last 60 mins&lt;BR /&gt;&lt;BR /&gt;i am getting below result&lt;BR /&gt;&lt;BR /&gt;ABC=1,DEF=2,GHI=3&lt;BR /&gt;ABC=0,DEF=0,GHI=0&lt;BR /&gt;&lt;BR /&gt;But i want only latest log result as like below&lt;BR /&gt;&lt;BR /&gt;ABC=1,DEF=2,GHI=3&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516084#M144956</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-25T17:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516094#M144960</link>
      <description>&lt;P&gt;Check out the &lt;FONT face="courier new,courier"&gt;dedup&lt;/FONT&gt; command.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:42:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516094#M144960</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-25T17:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516095#M144961</link>
      <description>&lt;P&gt;where should i use this command&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:44:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516095#M144961</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-25T17:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516096#M144962</link>
      <description>&lt;LI-CODE lang="markup"&gt;...
| head 1&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 25 Aug 2020 17:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516096#M144962</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-08-25T17:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516134#M144981</link>
      <description>Put it at the end of your current search.</description>
      <pubDate>Tue, 25 Aug 2020 19:22:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516134#M144981</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-25T19:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516184#M145031</link>
      <description>&lt;P&gt;I kept dedup command at the end but it didnt worked&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vinod0313_0-1598415435724.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10512iFFBA9A7D2F81C028/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vinod0313_0-1598415435724.png" alt="vinod0313_0-1598415435724.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 04:17:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516184#M145031</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-26T04:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516189#M145033</link>
      <description>&lt;P&gt;could any please help me to find the solution.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 05:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516189#M145033</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-26T05:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: latest</title>
      <link>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516199#M145036</link>
      <description>&lt;P&gt;Try limiting the number of events with head&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="cx_aws" source="notification-service"
| head 1
| spath ...&lt;/LI-CODE&gt;&lt;P&gt;I am not sure if this is the right query but it seems to be the one from your image. The point is that head will reduce the number of events from the base search, in this case to 1 i.e. the latest event&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 07:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/latest/m-p/516199#M145036</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-08-26T07:49:23Z</dc:date>
    </item>
  </channel>
</rss>

