Splunk Search

Count Last event by id and version

cros
Engager

Hi all, 

I'm trying to create a visualisation to show the percentage of ticket status (New, Comleted, Cancelled, etc.). 

I tried with this search : 

 

| stats latest(_time) as Time by "Record Number", PI_Number, PI_Event_Status

 

 

I have ticket with Record Number (id), Number (Version), Status. I want to take the last ticket event of the version and get his status. In order to count the current status of each event on the system. 

The result is the following : 

Record NumberNumberStatus_time
118671141Completed - Owner Action Required1472175180
118671141New1471951740
122975221Completed - Nothing Found1477321800
122975221Investigating1475829120
122975221New1475735400
122975222Completed - Error/Workaround Found1479229260
122975222New1479198300
122975223Completed - Recovery PTR Open1482241320
122975223New1482226920

 

With my stats command i'm not able to retrieve only last event for each version of a ticket. How i can do that ? 

 

Regards,

Clément

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats latest(_time) as Time, latest(PI_Event_Status) as PI_Event_Status by "Record Number", PI_Number
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...