Splunk Enterprise

We have a query where we need the EndDate to be the StartDate of the previous entry for all particular values in a row

shivareddysompa
Explorer

We have a query where we need the EndDate to be the StartDate of the previous entry for all particular values in a row

 

shivareddysompa_0-1593774776072.png

 

Labels (1)
Tags (1)
0 Karma

to4kawa
Ultra Champion

| autoregress StartDate as p_StartDate
| eval EndDate=if(EndDate!="",EndDate,p_StartDate)

0 Karma

shivareddysompa
Explorer

i want like End date will be next Start date and also 

 

Startdate               Endate 

10-02-2019         07-07-2020

07-07-2020         "blank "

 

blank indicates it is running

Tags (1)
0 Karma

to4kawa
Ultra Champion

your sample is too little.

please show the table what you want.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...