Getting Data In

How to get previous date values in the dashboard table apart from event data?

sekhar463
Path Finder

i have data in the event with date field 

and while saving the same search in the dashboard studio table its giving previous date values 

not giving exact values as event data

 

index=test sourcetype="test Data*"
| sort -time
| dedup TABLE_NAME
| table TABLE_NAME MAX_POSITION_DATE MAX_DMA_RUN_DATETIME

 

 TABLE_NAME          MAX_POSITION_DATE              MAX_DMA_RUN_DATETIME
5858585 L                2023-06-01 00:00:00.000         2023-06-01 06:48:12.225
46466464                 2023-05-31 00:00:00.000         2023-06-01 03:02:58.000

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming your time field is a numeric timestamp, the sort will put the events in descending time order i.e. latest first. The dedup will keep the first event in the pipeline for each table name.

Without seeing the exact data you are dealing with, it is not possible to say whether the values you are showing are correct or not, but given the above assumptions, if you are not getting the data you are expecting, you should look closer at your actual data to determine where the discrepancy may have arisen from.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...