Knowledge Management

Oldest 50 Tickest that are OPEN

cocomaster
Explorer

I am having hard times to query the Splunk.
The data in splunk is a list of tickets and their updates over time i.e:

TIMESTAMP,TICKET_1,STATE(open),ASSIGNED_TO,...
TIMESTAMP,TICKET_2,STATE(open),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(open),ASSIGNED_TO,...
TIMESTAMP,TICKET_2,STATE(in progress),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(in progress),ASSIGNED_TO,...
TIMESTAMP,TICKET_2,STATE(in progress),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(pending),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(on hold),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(in progress),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(in progress),ASSIGNED_TO,...
TIMESTAMP,TICKET_1,STATE(in progress),ASSIGNED_TO,...
TIMESTAMP,TICKET_2,STATE(closed),ASSIGNED_TO,...

I am looking for a way to find 50 Oldest tickets that are NOT closed.

How should i query the splunk knowing i have 5 years old database of tickets?

0 Karma

saurabh009
Path Finder

Try out this query:-
Index=indexName sourcetype=sourcetypeName |search STATE != "closed"|sort _time|head 50

Search for AllTime as your data is pretty old, this may take sometime.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...