Splunk Dev

Formatting outputs of latest events in multiple sourcetypes possible?

rome75
Engager

Hello, I am trying to take a search like this
index=public sourcetype=public1* OR sourcetype=public2* newyork* earliest=60m@m | convert ctime(_time) as time | stats latest(time) by device, sourcetype

device              sourcetype       latest(time)
newyorkdevice1      public1         11/10/2019 00:32:00.000
newyorkdevice1      public2         11/10/2019 00:32:00.000
newyorkdevice2      public1         11/10/2019 00:32:00.000
newyorkdevice2      public2         11/10/2019 00:32:00.000

and get an output like this

device          public1                     public2
newyorkdevice1    11/10/2019 00:32:00.000        11/10/2019 00:32:00.000
newyorkdevice2    11/10/2019 00:32:00.000        11/10/2019 00:32:00.000

Any help or advice is appreciated

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

@rome75,

Try chart command

index=public sourcetype=public1* OR sourcetype=public2* newyork* earliest=60m@m
|chart latest(_time) as _time over device by network
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

@rome75,

Try chart command

index=public sourcetype=public1* OR sourcetype=public2* newyork* earliest=60m@m
|chart latest(_time) as _time over device by network
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

rome75
Engager

Thank you for steering me in the right direction. I used chart and got the output I was looking for.

| convert ctime(_time) as time 
 | chart latest(time)  by device, sourcetype

 device    sourcetype_A        sourcetype_B
 newyorkdevice1    11/10/2019 00:32:00.000        11/10/2019 00:32:00.000
 newyorkdevice2    11/10/2019 00:32:00.000        11/10/2019 00:32:00.000
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...