Getting Data In

Can I make a field which contains the number of the entry, as a substitute for timestamp?

akcyril
New Member

I would like to experiment with entries in which time is mentioned as 1,2,3, .... , n; where the nth entry is the latest. Is this possible?

0 Karma

sundareshr
Legend

Look at streamstats command. You can use that to add a "counter" in reverse order to your events. Something like this may work base search | reverse | streamstats count

http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Streamstats

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...