Splunk Search

if multiple events at different time, only return most recent events based on a field

salt87
Engager

Hi,

I've got a search that returns me the following results:

Basically, I would like to only keep the most recent events for an IPAddress IF the field IPAddress has multiple events at 2 different time and discard the oldest event. In the case of the screenshot above, I would like to remove the highlighted line.

Would that be possible? Let me know if you need more information.

Thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

Add this to the bottom of your existing search:

... | streamstats count BY _time IPAddress
| where count == 1
0 Karma

woodcock
Esteemed Legend

Just add this to the bottom:

... | dedup IPAddress
0 Karma

salt87
Engager

Hi,

This won't work because I still need to see all events for an IPAddress. This will only show me one event per IP.

0 Karma

woodcock
Esteemed Legend

See my new answer.

0 Karma

arjunpkishore5
Motivator

Base on the example you provided

| stats values(pluginID) as pluginID by _time, IPAddress delim=","
| slats latest(pluginID) as pluginID, max(_time) as _time by IPAddress
| eval pluginID=split(pluginID,",")
| mvexpand pluginID 
0 Karma

salt87
Engager

Hi,

Unfortunately this is not working as it only shows one event for IP3 and not 2 events as shown in the OP screenshot.

This is the output:
IPAddress pluginID _time
IP1 94932 2019-11-01 04:19:23
IP2 46172 2019-11-08 20:32:25
IP3 108797 2019-10-31 02:00:21

What I would like is still keep both events for IP3 as per below:

IPAddress pluginID _time
IP1 94932 2019-11-01 04:19:23
IP2 46172 2019-11-08 20:32:25
IP3 108797 2019-10-31 02:00:21
IP3 84729 2019-10-31 02:00:21

Thanks

0 Karma

arjunpkishore5
Motivator

looks like latest is converting the mv field to a single value. Edited my answer. Please give it a try.

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...