Getting Data In

Find latest date for a record


Tried  a couple of functions ... nothing easy...

Example (index=XXX) AND event="XXXXXX" | eval tim =strftime(_time,"%m/%d/%Y") | eventstats max(tim) as maxDate| stats count by dvchost, maxDate

I need to figure out how to find the most recent records....  code does not work... looked at other ways to do it .... nothing easy... help


0 Karma


Hi @Stephen11 , please try this

 (index=XXX) AND event="XXXXXX" | stats latest(_time) as latestDate  by dvchost

|eval latestDate =strftime(latestDate ,"%m/%d/%Y")


Hope this helps!

Please upvote my response if this resolves the issue.

0 Karma



you should check also stat latest_time(_time) to see which one is the correct function for this time. Time by time those two gives different value. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...