Knowledge Management

How do you display a count based from the latest timestamp?

ejespiritu
Explorer

Hello, I'm new with Splunk and need some help.

I need to filter my data to only count the status of the latest time stamp for each ID.

I've a data set with 3 columns
ID, status, timestamp
1001, A, 11:12pm - should not count
1001, B, 11:13pm - should count
2002, A, 11:10pm - should not count
2002, A, 11:14pm - should count
3003, A, 11:11pm - should count

My dashboard should display
Status, Count
A, 2
B, 1

0 Karma
1 Solution

Shan
Builder

@ ejespiritu,

Try this approach ..

| makeresults
| eventstats latest(_time) as latest_timestamp by status
| where _time = latest_timestamp
| stats count(ID) by status 

View solution in original post

0 Karma

Shan
Builder

@ ejespiritu,

Try this approach ..

| makeresults
| eventstats latest(_time) as latest_timestamp by status
| where _time = latest_timestamp
| stats count(ID) by status 
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...