Splunk Search

First Everyday

reverse
Contributor

There are multiple CSVs which I generate on a daily basis.
Each CSV has some critical data & has 2 columns - _time & XX
I JOIN all CSVs to generate graphs.
The common column in each CSV is _time.

Now lets say I have 2 CSVs.

1 _time & XX 
2 _time & YY

I need to find earlier time and corresponding XX when yy=100 (first apperance)on a daily basis.. as CSVs are there since last 2 months with all the required data.

How can i achieve that ?

Tags (1)
0 Karma
1 Solution

reverse
Contributor
| eval mytime=strftime(_time, "%Y%m%d") 
| where x=100| dedup mytime
|sort _time | head 50

View solution in original post

0 Karma

reverse
Contributor
| eval mytime=strftime(_time, "%Y%m%d") 
| where x=100| dedup mytime
|sort _time | head 50
0 Karma

reverse
Contributor
| stats first(_time) by x | where x=100

Not working

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...