<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Display latest data in dashboard in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530055#M149757</link>
    <description>&lt;P&gt;If you are indexing the data , you still need to select a suitable time range unless you want to slow down your environment by using "All Time"&lt;/P&gt;&lt;P&gt;If different dates have same number of records/fields, then you can just use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="your index" .... 
|stats latest(your field list)&lt;/LI-CODE&gt;&lt;P&gt;However , above approach will not work if you have different number of fields/records for different dates.&lt;/P&gt;&lt;P&gt;In that case you may try below,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="your index" "other search terms"
|eval date=strftime(_time,"%d-%m-%Y")
|eventstats latest(date) as latest_date
|where date == latest_date&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2020 09:39:30 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2020-11-19T09:39:30Z</dc:date>
    <item>
      <title>Display latest data in dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530052#M149755</link>
      <description>&lt;P class="lia-align-justify"&gt;Hello all,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I have a requirement below :&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I'm pushing csv file(not pushing regularly) data to splunk index using splunk forwarder.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Using that data need to create a simple dashboard with tables and dropdowns.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;So my requirement is when ever i push data, only that data should be shown in dashboard (means latest data)&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Example,&amp;nbsp; if i push a csv file on 19th nov that data only should be displayed in table whenever i open that dashboard .&amp;nbsp; for suppose if i pushed again csv file on 23rd nov then tables should display data only for this date.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Here i don't want to change time manually in dashboard for every update.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;please suggest&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 08:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530052#M149755</guid>
      <dc:creator>kirrusk</dc:creator>
      <dc:date>2020-11-19T08:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Display latest data in dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530055#M149757</link>
      <description>&lt;P&gt;If you are indexing the data , you still need to select a suitable time range unless you want to slow down your environment by using "All Time"&lt;/P&gt;&lt;P&gt;If different dates have same number of records/fields, then you can just use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="your index" .... 
|stats latest(your field list)&lt;/LI-CODE&gt;&lt;P&gt;However , above approach will not work if you have different number of fields/records for different dates.&lt;/P&gt;&lt;P&gt;In that case you may try below,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="your index" "other search terms"
|eval date=strftime(_time,"%d-%m-%Y")
|eventstats latest(date) as latest_date
|where date == latest_date&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 09:39:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530055#M149757</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-11-19T09:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Display latest data in dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530069#M149759</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&amp;nbsp; still not working&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example, today no data pushed to splunk but i want to display latest results with out selecting the dynamic time.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 11:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530069#M149759</guid>
      <dc:creator>kirrusk</dc:creator>
      <dc:date>2020-11-19T11:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Display latest data in dashboard</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530149#M149789</link>
      <description>&lt;P&gt;Which part is not working ? As mentioned above you need to select a suitable time range to list the events regardless of how often you send&amp;nbsp; the data. For e.g. If you are sending data once in a month, you need to select a time range to get data from last month from the index since the events are stored with a&amp;nbsp; timestamp. Is this working ?&lt;/P&gt;&lt;P&gt;Alternatively you may consider a lookup file instead of indexing the data if you do not want to select a time range at all.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 01:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-latest-data-in-dashboard/m-p/530149#M149789</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-11-20T01:07:13Z</dc:date>
    </item>
  </channel>
</rss>

