Getting Data In

Find latest date for a record

Stephen11
Explorer

Tried  a couple of functions ... nothing easy...

Example (index=XXX) AND event="XXXXXX" | eval tim =strftime(_time,"%m/%d/%Y") | eventstats max(tim) as maxDate| stats count by dvchost, maxDate

I need to figure out how to find the most recent records....  code does not work... looked at other ways to do it .... nothing easy... help

 

0 Karma

Nisha18789
Builder

Hi @Stephen11 , please try this

 (index=XXX) AND event="XXXXXX" | stats latest(_time) as latestDate  by dvchost

|eval latestDate =strftime(latestDate ,"%m/%d/%Y")

 

Hope this helps!

Please upvote my response if this resolves the issue.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you should check also stat latest_time(_time) to see which one is the correct function for this time. Time by time those two gives different value. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...