- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gmasca
Explorer
12-04-2018
07:11 AM
Hi,
I am new to Splunk and I am trying the following, but I can't find how.
I need to create a dashboard showing the results of pooling on a value from multiple devices.
I like to show in the same line device, earliest result, and oldest result.
I can make the list of results and merge them into one line per device, but not separate the earliest and oldest results in columns
Example:
Data from the pooling
host1, value 1, time: 1/12/2018 11:00
host2, value 2, time: 1/12/2018 11:00
host1, value 3, time: 1/12/2018 11:05
host2, value 4, time: 1/12/2018 11:05
Dashboard:
host / earlist / oldest
host1 / 3 / 1
host2 / 4 / 2
Any help is much appreciated.
Thank you,
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
whrg
Motivator
12-04-2018
07:24 AM
Hi!
Try this:
basesearch | stats earliest(value) as earliest latest(value) as oldest by host
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
whrg
Motivator
12-04-2018
07:24 AM
Hi!
Try this:
basesearch | stats earliest(value) as earliest latest(value) as oldest by host
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gmasca
Explorer
12-04-2018
07:46 AM
Thanks! It worked.
