Splunk Search

Count Last event by id and version

cros
Engager

Hi all, 

I'm trying to create a visualisation to show the percentage of ticket status (New, Comleted, Cancelled, etc.). 

I tried with this search : 

 

| stats latest(_time) as Time by "Record Number", PI_Number, PI_Event_Status

 

 

I have ticket with Record Number (id), Number (Version), Status. I want to take the last ticket event of the version and get his status. In order to count the current status of each event on the system. 

The result is the following : 

Record NumberNumberStatus_time
118671141Completed - Owner Action Required1472175180
118671141New1471951740
122975221Completed - Nothing Found1477321800
122975221Investigating1475829120
122975221New1475735400
122975222Completed - Error/Workaround Found1479229260
122975222New1479198300
122975223Completed - Recovery PTR Open1482241320
122975223New1482226920

 

With my stats command i'm not able to retrieve only last event for each version of a ticket. How i can do that ? 

 

Regards,

Clément

Labels (2)
0 Karma

ITWhisperer
Legend
| stats latest(_time) as Time, latest(PI_Event_Status) as PI_Event_Status by "Record Number", PI_Number
0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.