Splunk Search

Getting the timestamp when the status has changed

New Member

We are getting the data from Database for every 5mins.

Even the field value doesn't change the same value will be indexed with different timestamp for every 5 mins.

There is a status field which indicates whether the device is on or off.

we want to get the time of the status change for the device with the timestamp.

please suggest the query for this

Labels (1)
0 Karma


Hi @honey527,

Please try below;

| dedup _time status
| table _time status


If this reply helps you an upvote is appreciated.
0 Karma