<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking for multiple results in query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434779#M167020</link>
    <description>&lt;P&gt;Are you using this query?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-TST6/" | stats latest(_time) as tst6t by job_result
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 15 Oct 2018 21:42:39 GMT</pubDate>
    <dc:creator>Vijeta</dc:creator>
    <dc:date>2018-10-15T21:42:39Z</dc:date>
    <item>
      <title>Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434774#M167015</link>
      <description>&lt;P&gt;I have the following query I use to get the latest status and time(_time).&lt;/P&gt;

&lt;P&gt;index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-TST6/" | sort -_time | stats latest(job_result) as status, latest(_time) as tst6t&lt;/P&gt;

&lt;P&gt;Now, I want to get the time(_time) of the job that run successfully -&amp;gt; job_result=SUCCESS. I wanyt to seew if I can get those two times from the same query and display them inside the same dashboard panel. I tried different ways and could not get it working.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434774#M167015</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2020-09-29T21:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434775#M167016</link>
      <description>&lt;P&gt;Try this :-&lt;/P&gt;

&lt;P&gt;ME TOO&lt;BR /&gt;
I have the following query I use to get the latest status and time(_time).&lt;/P&gt;

&lt;P&gt;‘index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-TST6/" | sort -_time | stats latest(job_result) as status, latest(eval(job_result=“SUCCESS”)) ,latest(_time) as tst6t`&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434775#M167016</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2020-09-29T21:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434776#M167017</link>
      <description>&lt;P&gt;I changed it to:&lt;/P&gt;

&lt;P&gt;stats latest(job_result) as dev2status, latest(_time=if(eval(job_result=“SUCCESS”))) as dev2st, latest(_time) as dev2t&lt;/P&gt;

&lt;P&gt;It  did not pickup the _time for the latest successful job run...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434776#M167017</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2020-09-29T21:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434777#M167018</link>
      <description>&lt;P&gt;Can you do this and see if it suffices your requirement-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;stats  latest(_time) as tst6t` by job_result
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 15 Oct 2018 19:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434777#M167018</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-15T19:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434778#M167019</link>
      <description>&lt;P&gt;I used "latest(_time) as dev2st by job_result" in the stats command and the it did not get anything. I am getting "no results found" in the panel.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434778#M167019</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2020-09-29T21:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434779#M167020</link>
      <description>&lt;P&gt;Are you using this query?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-TST6/" | stats latest(_time) as tst6t by job_result
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 15 Oct 2018 21:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434779#M167020</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-15T21:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434780#M167021</link>
      <description>&lt;P&gt;index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-DEV2/" | sort -_time | stats latest(job_result) as dev2status, latest(_time) as dev2st by job_result, latest(_time) as dev2t&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434780#M167021</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2020-09-29T21:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434781#M167022</link>
      <description>&lt;P&gt;Please try with the above query in my comments&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 22:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434781#M167022</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-15T22:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434782#M167023</link>
      <description>&lt;P&gt;How can I get two time values? one for the latest run, and one for the success run in your query?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 22:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434782#M167023</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2018-10-15T22:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434783#M167024</link>
      <description>&lt;P&gt;you will get the latest time for each unique value in job_result. Once you get that you need to sort - dev2t. This will give you the latest job result name and also the row with value SUCCESS will give you latest time for success.&lt;/P&gt;

&lt;P&gt;Can you paste your results here with the above query&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 22:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434783#M167024</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-15T22:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434784#M167025</link>
      <description>&lt;P&gt;I got two results:&lt;/P&gt;

&lt;P&gt;job_result .     tst6t&lt;BR /&gt;
FAILURE .        1539707765.083&lt;BR /&gt;
SUCCESS .       1539704175.318&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 16:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434784#M167025</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2018-10-16T16:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434785#M167026</link>
      <description>&lt;P&gt;This gives you the latest time of Failure and Success and if you sort - tst6t, it will give you the latest event among the 2 events.&lt;BR /&gt;
Also you can convert the time in yyyy/mm/dd format using below command at end of yiur query&lt;/P&gt;

&lt;P&gt;| eval tst6t = strftime(tst6t,"%Y/%m/%d %H:%M:%S")&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 16:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434785#M167026</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-16T16:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434786#M167027</link>
      <description>&lt;P&gt;tst6t only have the two times, how do i know which one is for "SUCCESS" and whicch one is for "FAILURE"?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 17:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434786#M167027</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2018-10-16T17:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434787#M167028</link>
      <description>&lt;P&gt;You have the job_result column in your output against the time . &lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 18:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434787#M167028</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-16T18:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434788#M167029</link>
      <description>&lt;P&gt;sorry i am not sure how to retrieve them individually as i am new to splunk and xml &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 16:45:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434788#M167029</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2018-10-18T16:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434789#M167030</link>
      <description>&lt;P&gt;I am not sure what your end goal is , the output you have is which gives you latest time of each job_result. Please specify what you need to do with this data&lt;/P&gt;

&lt;P&gt;job_result . tst6t&lt;BR /&gt;
FAILURE . 1539707765.083&lt;BR /&gt;
SUCCESS . 1539704175.318&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 16:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434789#M167030</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-18T16:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434790#M167031</link>
      <description>&lt;P&gt;I want to display the last run time in the panel title field, and the last success run time in the single value title field.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 16:56:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434790#M167031</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2018-10-18T16:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for multiple results in query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434791#M167032</link>
      <description>&lt;P&gt;In another word, I want to do something like:&lt;/P&gt;

&lt;P&gt;index=jenkins |spath job_name | search job_name="job/utl-dataflow-check-TST6/" | stats latest(_time) as tst6t by job_result | ... tst6t_success_time ... | ... tst6t_failure_time...&lt;/P&gt;

&lt;P&gt;tst6t_success_time and tst6t_failure_time are from tst6t. No idea how to pick them up from tst6t...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Looking-for-multiple-results-in-query/m-p/434791#M167032</guid>
      <dc:creator>pshangguan</dc:creator>
      <dc:date>2020-09-29T21:42:53Z</dc:date>
    </item>
  </channel>
</rss>

