Alerting

Fetch latest timestamp of search records

anmohan0
Explorer

Hi,

I would like to get the latest search record or multiple search combination.

For example, if my search is as below

index=myIndex ABCD AND (Input OR Error)

I am expecting output as below table format

Component | Last Input Timestamp| Last Errored Timestamp

ABCD             | 24-03-2024 12:23:23| 24-03-2024 08:23:12

Search should fetch the timestamp of latest log event of (ABCD and Input) and (ABCD and Error). 

Tags (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| stats latest(eval(if(searchmatch("Error"),_time,null()))) as LastErroredTimestamp latest(eval(if(searchmatch("Input"),_time,null()))) as LastInputTimestamp by Component
| fieldformat LastErroredTimestamp=strftime(LastErroredTimestamp,"%F %T")
| fieldformat LastInputTimestamp=strftime(LastInputTimestamp,"%F %T")

View solution in original post

0 Karma

anmohan0
Explorer

Thanks a lot @ITWhisperer , you saved me and it works seamlessly the way I wanted

0 Karma

anmohan0
Explorer

@ITWhisperer Thank you very much and you made my day to achieve the desired output.

Also I would like to pass Component as a dropdown which could be either 1 or 2 or 3 comma separated values as AAAA, BBBB, CCCC and expecting output for each component it should display the Last Input Timestamp and Last Output Timestamp

Component | Last Input Timestamp| Last Errored Timestamp

AAAA             | 24-03-2024 12:23:23| 24-03-2024 08:23:12

BBBB             | 23-03-2024 10:12:44| 24-02-2024 05:45:22

CCCC             | 12-05-2024 11:01:00| 04-05-2024 01:23:12

Any help to achieve this would be really appreciated!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is a different question - you could modify your search to use something like Component IN $componentselection$ but it depends on how your dashboard is set up

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats latest(eval(if(searchmatch("Error"),_time,null()))) as LastErroredTimestamp latest(eval(if(searchmatch("Input"),_time,null()))) as LastInputTimestamp by Component
| fieldformat LastErroredTimestamp=strftime(LastErroredTimestamp,"%F %T")
| fieldformat LastInputTimestamp=strftime(LastInputTimestamp,"%F %T")
0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...