Splunk Search

DB Query dumps a table. How do I search only on the most recent table snapshot?

ocallender
Explorer

Hi folks,
This might be elementary, but here goes:

I have a Database input that grabs all open tickets from our helpdesk system. This runs every 5 minutes. So I end up with a nice index of table snapshots and I can create nice timecharts with span=5m showing how metrics change (every 5 minutes).

But what if I wanted to visualise a pie chart showing currently open vs on-hold tickets? All of that data would come from the last data dump that was done. The quick and dirty solution i found was to set the tme reange as 5 minute window. That way, the chart updates each time a data dump is done and ignores the data from teh last dump because it happened more than 5 minutes ago.

I guess this works, but if I change the pooling interval to 10 minutes, I'd have to change the time window to match the polling rate in all of my dashboards. I can't help thinking that there is a better way.

Regards,
Okolo

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

This should give you the latest status value for tickets:

index=your_index status="open" OR status="on_hold" | stats latest(status) as status by ticket_number | ...

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

This should give you the latest status value for tickets:

index=your_index status="open" OR status="on_hold" | stats latest(status) as status by ticket_number | ...
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...