<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stats Command and timestamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558153#M158528</link>
    <description>&lt;P&gt;Is that data sample complete?&amp;nbsp; If so, then the null fields explains why the stat command fails.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jul 2021 12:44:33 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-07-02T12:44:33Z</dc:date>
    <item>
      <title>Stats Command and timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558056#M158489</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I am using a stats command with a "by" time field, but i am not getting the result.&lt;/P&gt;&lt;P&gt;If i remove the time field i am getting the desired result.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want all the fields in my outcome, how to obtain.&lt;/P&gt;&lt;P&gt;stats latest(et) as "ET" by status, id,&amp;nbsp;&lt;FONT color="#FF6600"&gt;starttime - If i remove this "starttime" i am getting the outcome but i need that also in my outcome. Can i put a separate table? but there also this column is not showing.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;I want all these fields ET,Status,id,Startime&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;What to do?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 18:00:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558056#M158489</guid>
      <dc:creator>chuck_life09</dc:creator>
      <dc:date>2021-07-01T18:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Stats Command and timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558067#M158499</link>
      <description>&lt;P&gt;Make sure the starttime field exists and has values in it.&amp;nbsp; The stats command will not produce results if one of the "by" fields is null.&lt;/P&gt;&lt;P&gt;It would help if you shared some sample data and a mock-up of the desired results.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 19:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558067#M158499</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-01T19:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Stats Command and timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558077#M158505</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample data&lt;/P&gt;&lt;P&gt;Et&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;I'd&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; starttime&lt;/P&gt;&lt;P&gt;2021/07/01 04:00:00&amp;nbsp; &amp;nbsp; &amp;nbsp;fa&lt;SPAN&gt;iled&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; abcf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021/07/01 03:24:00&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 23:04:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558077#M158505</guid>
      <dc:creator>chuck_life09</dc:creator>
      <dc:date>2021-07-01T23:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Stats Command and timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558153#M158528</link>
      <description>&lt;P&gt;Is that data sample complete?&amp;nbsp; If so, then the null fields explains why the stat command fails.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 12:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Stats-Command-and-timestamp/m-p/558153#M158528</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-02T12:44:33Z</dc:date>
    </item>
  </channel>
</rss>

