Splunk Search

How can I get the latest result?

abi2023
Path Finder

my spl 
base search |transaction ID | table date field1 field2 ID

my result 

 

Date                 field1      fiel2         ID
02/20/23        CCC        2k               10

02/20/23         c2           4k                11

02/10/23.         CC          2k             08

02/01/23           C             5k              01

but I only want to output latest result which 02/20/23 assuming begin of the I don't date for latest event. 

 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Is your date field different to _time? Also, you have two dates the same value, but if date is different to _time then do this

 

base search 
| transaction ID 
| eval tmp=strptime(date, "%m/%d/%y")
| sort 1 - tmp
| table date field1 field2 ID

 

if date is the same as _time then you just need

base search 
| transaction ID 
| sort 1 - _time
| table date field1 field2 ID

but how do you want to differentiate between the first two events that have the same date?

 

0 Karma

somesoni2
Revered Legend

Give this a try

base search |transaction ID | table date field1 field2 ID
| eventstats latest(date) as latestDate
| where date=latestDate | fields - latestDate
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...