Splunk Enterprise

We have a query where we need the EndDate to be the StartDate of the previous entry for all particular values in a row

shivareddysompa
Explorer

We have a query where we need the EndDate to be the StartDate of the previous entry for all particular values in a row

 

shivareddysompa_0-1593774776072.png

 

Labels (1)
Tags (1)
0 Karma

to4kawa
Ultra Champion

| autoregress StartDate as p_StartDate
| eval EndDate=if(EndDate!="",EndDate,p_StartDate)

0 Karma

shivareddysompa
Explorer

i want like End date will be next Start date and also 

 

Startdate               Endate 

10-02-2019         07-07-2020

07-07-2020         "blank "

 

blank indicates it is running

Tags (1)
0 Karma

to4kawa
Ultra Champion

your sample is too little.

please show the table what you want.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...