<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eval in stats with max in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707358#M239262</link>
    <description>&lt;P&gt;Ahh... ok. If it is suppossed to mean all results for the max value of field1, it's also a relatively easy to use sort and streamstats.&lt;/P&gt;&lt;P&gt;Your typical&lt;/P&gt;&lt;PRE&gt;| sort - field1&lt;/PRE&gt;&lt;P&gt;will give you your data sorted in descending order. That means that you have your max values first. This in turn means that you don't have to eventstats over whole resukt set. Just use streamstats to copy over the first value which must be the maximum value.&lt;/P&gt;&lt;PRE&gt;| streamstats current=t first(field1) as field1max&lt;/PRE&gt;&lt;P&gt;Now all that's left is to filter&lt;/P&gt;&lt;PRE&gt;| where field1=field1max&lt;/PRE&gt;&lt;P&gt;Since we're operating on our initial result we've retained all original fields.&lt;/P&gt;&lt;P&gt;Of course for for additional performance boost you can remove unnecessary fields prior to sorting so you don't needlessly drag them around just to get rid of them immediately after if you have a big data set to sort.(Same goes for limiting your processed data volume in with eventstats-based solution)&lt;/P&gt;</description>
    <pubDate>Fri, 20 Dec 2024 07:24:31 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-12-20T07:24:31Z</dc:date>
    <item>
      <title>eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707177#M239223</link>
      <description>&lt;P&gt;Hi at all,&lt;/P&gt;&lt;P&gt;I have a data structure like the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;title1 title2 title3 title4 value&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and I need to group by title1 and having title4 where value (numeric field) is max.&lt;/P&gt;&lt;P&gt;How can I use eval in stats to have this?&lt;/P&gt;&lt;P&gt;something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(eval(title4 where value is max)) AS title4 BY title1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I do it?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 16:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707177#M239223</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-18T16:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707197#M239225</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;Maybe eventstats to add additional field where is title4’s values based on max value? I know that this is not an efficient way, but it’s first which comes into my mind. Probably there is better ways &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;?&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 18:01:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707197#M239225</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-18T18:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707204#M239226</link>
      <description>&lt;P&gt;I agree.&amp;nbsp; I would try &lt;FONT face="courier new,courier"&gt;eventstats&lt;/FONT&gt; as well.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 18:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707204#M239226</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-12-18T18:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707232#M239227</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;a couple of ways with eventstats&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults count=300
| fields - _time
| eval title1="Title".mvindex(split("ABC",""), random() % 3)
| eval value=random() % 100
| eval title4="Title4-".mvindex(split("ZYXWVUTSRQ",""), random() % 10)
``` Data creation above ```
| eventstats max(value) as max_val by title1
| stats values(eval(if(value=max_val, title4, null()))) as title4 max(max_val) as max_val by title1&lt;/LI-CODE&gt;&lt;P&gt;Or depending on your title4 data you can put in another stats, i.e. after the data set up above, do&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;``` Reduce the data first before the eventstats ```
| stats max(value) as max_val by title1 title4
| eventstats max(max_val) as max by title1
| stats values(eval(if(max_val=max, title4, null()))) as title4 max(max) as max by title1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;This way the eventstats works on a far smaller dataset, depending on your cardinality&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 21:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707232#M239227</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-12-18T21:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707233#M239228</link>
      <description>&lt;P&gt;Yup. +1 on eventstats. Stats will aggregate all data leaving you with just max value. Appendpipe will append stats at the end but you'll still have them as a separate entity. You could use subsearch but it would be ugly and ineffective (you'd have to run the main search twice effectively). Eventstats it is.&lt;/P&gt;&lt;P&gt;But since eventstats has limitations, you can cheat a little.&lt;/P&gt;&lt;PRE&gt;| sort - title1 title4&lt;BR /&gt;| dedup title1&lt;/PRE&gt;&lt;P&gt;It doesn't replace eventstats in a general case but for max or min value it might be a bit quicker than eventstats and will almost surely have lower memory footprint.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 10:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707233#M239228</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-19T10:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707296#M239242</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@all,&lt;/P&gt;&lt;P&gt;Thank you for all your hints, but my issue is that I must find the title4, for each title1 where value is max, with this solution I find the max value for each title1, not the title4 where value is max and relative value for each title1.&lt;/P&gt;&lt;P&gt;Have you any other hint?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 14:41:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707296#M239242</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-19T14:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707331#M239253</link>
      <description>&lt;P&gt;Ok. Honestly, I'm a bit confused. I don't understand what you mean by "where value is max".&lt;/P&gt;&lt;P&gt;As I understand it if you have&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;title1&lt;/TD&gt;&lt;TD width="50%"&gt;title4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;TD width="50%"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;TD width="50%"&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;TD width="50%"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;You want&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;title1&lt;/TD&gt;&lt;TD width="50%"&gt;title4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;TD width="50%"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;TD width="50%"&gt;7&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;as a result because for each value of title1 you want the max value of title4, no?&lt;/P&gt;&lt;P&gt;Maybe we just misunderstand each other...&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 20:21:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707331#M239253</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-19T20:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707338#M239255</link>
      <description>&lt;P&gt;I too don't quite get your statement "&lt;SPAN&gt;where value is max"&amp;nbsp;&lt;/SPAN&gt; - you said you have&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;title1 title2 title3 title4 value&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I assumed titles are text elements and the value is numeric. Does the table below model your data or is it different?&lt;/P&gt;&lt;P&gt;title1 title4 value &amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;TitleC&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;16&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;69&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;83&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleC&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;92&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;45&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;90&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;87&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;97&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;54&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;85&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleC&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;58&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleC&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;18&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleC&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;31&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;38&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;46&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;57&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleA&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;27&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TitleB&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;71&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;What does max in your description represent?&amp;nbsp; I understood you want all the values of title4 "&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;where value is max&lt;/FONT&gt;". Can you define what max is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For title4-X, Y and Z the max of values by title 4 are 92, 97 and 71.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For title1-A, B and C the max of values by title1 are 90, 97 and 92.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do either of these describe your 'max'.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An example would be useful?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 22:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707338#M239255</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-12-19T22:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707350#M239258</link>
      <description>&lt;P&gt;Lol we are all secretly trying to decipher the sentence&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&amp;nbsp;(I thought&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;had both methods covered when I read this last night.) &amp;nbsp;OK, I think I cranked the code. &amp;nbsp;Using the same strategy (but deterministic for easy validation) I constructed this mock dataset:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;title1&lt;/TD&gt;&lt;TD&gt;title4&lt;/TD&gt;&lt;TD&gt;value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-W&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-V&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-U&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-T&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-S&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-R&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-Q&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-W&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-V&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-U&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-T&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-S&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-R&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-Q&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-Z&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-Y&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-X&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-W&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;Title4-V&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;Title4-U&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I think the semantics is: Find the Title4 that corresponds to the maximum value in the whole set - in this case, Title4-Q and Title4-V, as it corresponds to value 4; then, find all rows with these Title4 group them by Title1. I.e.,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eventstats max(value) as max_val
| where value == max_val
| stats values(title4) as title4 by title1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output for the mock data is&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;title1&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;title4&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:A&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Title4-Q&lt;/DIV&gt;&lt;DIV class=""&gt;Title4-V&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:B&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Title4-Q&lt;/DIV&gt;&lt;DIV class=""&gt;Title4-V&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Title1:C&lt;/TD&gt;&lt;TD&gt;Title4-V&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is the emulation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults count=25
| streamstats count
| eval value = count % 5
| eval title1="Title1:".mvindex(split("ABCDE",""), count % 3)
| eval title4="Title4-".mvindex(split("ZYXWVUTSRQ",""), count % 10)
| fields - _time count
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Similarly a double-stats strategy can be construed.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 04:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707350#M239258</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-12-20T04:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707358#M239262</link>
      <description>&lt;P&gt;Ahh... ok. If it is suppossed to mean all results for the max value of field1, it's also a relatively easy to use sort and streamstats.&lt;/P&gt;&lt;P&gt;Your typical&lt;/P&gt;&lt;PRE&gt;| sort - field1&lt;/PRE&gt;&lt;P&gt;will give you your data sorted in descending order. That means that you have your max values first. This in turn means that you don't have to eventstats over whole resukt set. Just use streamstats to copy over the first value which must be the maximum value.&lt;/P&gt;&lt;PRE&gt;| streamstats current=t first(field1) as field1max&lt;/PRE&gt;&lt;P&gt;Now all that's left is to filter&lt;/P&gt;&lt;PRE&gt;| where field1=field1max&lt;/PRE&gt;&lt;P&gt;Since we're operating on our initial result we've retained all original fields.&lt;/P&gt;&lt;P&gt;Of course for for additional performance boost you can remove unnecessary fields prior to sorting so you don't needlessly drag them around just to get rid of them immediately after if you have a big data set to sort.(Same goes for limiting your processed data volume in with eventstats-based solution)&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 07:24:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707358#M239262</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-20T07:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707388#M239272</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I used all your solutions to have this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eventstats max(alert_level) as max_val BY title1
            | stats 
               values(eval(if(alert_level=max_val,title4,""))) AS title4
               max(alert_level) AS alert_level 
               BY title1&lt;/LI-CODE&gt;&lt;P&gt;Thank you for you all support.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 13:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707388#M239272</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-20T13:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: eval in stats with max</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707393#M239273</link>
      <description>&lt;P&gt;Ahhhh... You had yet another field _called_ value. I suppose we all missed that and assumed "value" meant the value of one of the title* fields, not a separate field. *facepalm*&lt;/P&gt;&lt;P&gt;In this case, you can still avoid using eventstats&lt;/P&gt;&lt;PRE&gt;| sort - alert_level title1&lt;BR /&gt;| streamstats current=t dc(alert_level) as selector by title1&lt;BR /&gt;| where selector=1&lt;BR /&gt;| stats values(title4) as title4s by title1&lt;/PRE&gt;&lt;P&gt;Don't get me wrong - eventstats is a powerful and useful command but with some bigger datasets you might consider alternatives.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 15:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eval-in-stats-with-max/m-p/707393#M239273</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-20T15:41:25Z</dc:date>
    </item>
  </channel>
</rss>

