Hello,
This is the query that I am working on. Its showing multiple time entries. How do we get it to filter down to single entry?
(index=xyz source=abc) SMF30JBN=MC2DC03D SMF30JNM=JOB* SMF30STP=5
| table DATETIME SMF30JBN SMF30STP SMF30JNM SMF30STM
Thank you,
Chinmay.
| sort 1 -DATETIME
Assuming DATETIME is an epoch time and you want just the latest event
Sometimes deduct with sortby can also help you. https://docs.splunk.com/Documentation/Splunk/8.2.1/SearchReference/Dedup
r. Ismo