<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to maintain latest value for multiple values of a field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-maintain-latest-value-for-multiple-values-of-a-field/m-p/534543#M151059</link>
    <description>&lt;LI-CODE lang="markup"&gt;|makeresults
| eval _raw="HOST	VALUE
Host1	1
Host2	4
Host3	2
Host2	7
Host3	5
Host1	8"
| multikv forceheader=1
| table HOST VALUE
| rename COMMENT as "this is your sample. from here, the logic"
| reverse
| streamstats count
| reverse
| eval tmp=count."_".HOST."_".VALUE
| streamstats values(tmp) as tmp
| streamstats count as session
| mvexpand tmp
| rex field=tmp "\d_(?&amp;lt;HOST&amp;gt;\w+)_(?&amp;lt;VALUE&amp;gt;\d)"
| streamstats first(VALUE) as VALUE by session HOST
| eval tmp2=HOST."-".VALUE
| streamstats first(HOST) as HOST first(VALUE) as VALUE values(tmp2) as LATEST by session 
| stats values(LATEST) as LATEST by session HOST VALUE delim=","
| fields - session
| nomv LATEST&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 31 Dec 2020 08:37:14 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-12-31T08:37:14Z</dc:date>
    <item>
      <title>How to maintain latest value for multiple values of a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-maintain-latest-value-for-multiple-values-of-a-field/m-p/534488#M151045</link>
      <description>&lt;P&gt;Given the following events&lt;/P&gt;&lt;TABLE border="1" width="36%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;HOST&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;VALUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;Host1&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;Host2&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;Host3&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Host2&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Host3&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Host1&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I maintain the latest value for each host to give result like below?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE border="1" width="24.903474903474905%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;HOST&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;VALUE&lt;/TD&gt;&lt;TD width="12.5%"&gt;LATEST&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Host1&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="12.5%"&gt;Host1-1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Host2&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;4&lt;/TD&gt;&lt;TD width="12.5%"&gt;Host1-1,Host2-4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Host3&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;2&lt;/TD&gt;&lt;TD width="12.5%"&gt;Host1-1, Host2-4, Host3-2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Host2&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;7&lt;/TD&gt;&lt;TD width="12.5%"&gt;Host1-1, Host2-7, Host3-2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Host3&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;5&lt;/TD&gt;&lt;TD width="12.5%"&gt;Host1-1, Host2-7, Host3-5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;Host1&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;8&lt;/TD&gt;&lt;TD width="12.5%"&gt;Host1-8, Host2-7, Host3-5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 30 Dec 2020 14:46:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-maintain-latest-value-for-multiple-values-of-a-field/m-p/534488#M151045</guid>
      <dc:creator>timbilt</dc:creator>
      <dc:date>2020-12-30T14:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to maintain latest value for multiple values of a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-maintain-latest-value-for-multiple-values-of-a-field/m-p/534543#M151059</link>
      <description>&lt;LI-CODE lang="markup"&gt;|makeresults
| eval _raw="HOST	VALUE
Host1	1
Host2	4
Host3	2
Host2	7
Host3	5
Host1	8"
| multikv forceheader=1
| table HOST VALUE
| rename COMMENT as "this is your sample. from here, the logic"
| reverse
| streamstats count
| reverse
| eval tmp=count."_".HOST."_".VALUE
| streamstats values(tmp) as tmp
| streamstats count as session
| mvexpand tmp
| rex field=tmp "\d_(?&amp;lt;HOST&amp;gt;\w+)_(?&amp;lt;VALUE&amp;gt;\d)"
| streamstats first(VALUE) as VALUE by session HOST
| eval tmp2=HOST."-".VALUE
| streamstats first(HOST) as HOST first(VALUE) as VALUE values(tmp2) as LATEST by session 
| stats values(LATEST) as LATEST by session HOST VALUE delim=","
| fields - session
| nomv LATEST&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 31 Dec 2020 08:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-maintain-latest-value-for-multiple-values-of-a-field/m-p/534543#M151059</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-12-31T08:37:14Z</dc:date>
    </item>
  </channel>
</rss>

