Dashboards & Visualizations

How to chart the 5 most recent events?

merdenoms
Loves-to-Learn Everything

How can I chart/graph out the 5 most recent events?

When an event occurs, the data/time is stored in whenCreated.  whenCreated has the format of 00:00.00 AM, Weekday DD/MM/YYYY.  Can I use this format?

I want to print the eventName and whenCreated.  But dedup eventName so that it only shows different values.

Here is my normal query:

 

index=main admonEventType=* | sort - whenCreated | dedup eventName | table eventName whenCreated | head 5

 

It looks like I can possibly do this with a statistics table using:

 

| chart values(*) by eventName

 

Could I put this in a bar chart?

 

Labels (2)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Times in string form will not sort as you might expect so they should be converted into epoch (integer) form before sorting.  Try this

index=main admonEventType=* 
| eval sortTime = strptime(whenCreated, "%H:%M.%S %p, %A %d/%m/%Y")
| sort - sortTime
| dedup eventName 
| table eventName whenCreated 
| head 5
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...