Splunk Search

Earliest entry for each host

pitmod
Explorer

Hello,

In my lookup I have the following data:

_time='2020-10-21 15:00' usage='1' host='A'
_time='2020-10-26 15:00' usage='2' host='B'
_time='2020-10-21 16:00' usage='3' host='A'
_time='2020-10-23 18:00' usage='4' host='A'
_time='2020-10-24 15:00' usage='2' host='B'


I want to get only the earliest entry for each host so it will look like this:


host='A' _time='2020-10-21 15:00' usage='1'
host='B' _time='2020-10-24 15:00' usage='2'

How can I do it?

Labels (2)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

| stats earliest(_time) as _time earliest(usage) as usage by host

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

| stats earliest(_time) as _time earliest(usage) as usage by host

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...