I am new to splunk. I have a need to get the visualization which shows the field of the corresponding stats value.
Data looks like
I want show.:
Below query gets me the stats value, but i don't know how to get the corresponding stat_date for each of this.
| stats sum(mbFileSize) AS "Size", dc(FileName) AS "Files" by stat_date
| stats min(Size) as min_size max(Size) as max_size min(Files) as min_file max(Files) as max_file
Thank you
| stats sum(mbFileSize) AS "Size", dc(FileName) AS "Files" by stat_date
| eventstats min(Size) as min_size max(Size) as max_size
| eval min=case(min_size=Size,Size),max=case(max_size=Size,Size),min_size_date=case(min_size=Size,stat_date),max_size_date=case(max_size=Size,stat_date)
| fields min,min_size_date,max,max_size_date
| stats values(*) as *
| rename min as min_size, max as max_size
| table min_size min_size_date max_size max_size_date
thank you @thambisetty ! It worked exactly like what i was looking for.. Appreciate your help!
| stats sum(mbFileSize) AS "Size", dc(FileName) AS "Files" by stat_date
| eventstats min(Size) as min_size max(Size) as max_size
| eval min=case(min_size=Size,Size),max=case(max_size=Size,Size),min_size_date=case(min_size=Size,stat_date),max_size_date=case(max_size=Size,stat_date)
| fields min,min_size_date,max,max_size_date
| stats values(*) as *
| rename min as min_size, max as max_size
| table min_size min_size_date max_size max_size_date
Thank you @thambisetty .
My need here is to get the corresponding stat_date for min and max value on the data.. Sorry if I wasn't clear on initial question.
Here in this case, min_size corresponds to stat_date as 09/05/2020 and max_size corresponds to stat_date as 09/06/2020
min_size | min_size_date | max_size | max_size_date |
5.02 | 09/05/2020 | 52.28 | 09/06/2020 |