Splunk Search
Highlighted

How do you get a table of most recent events with multiple fields?

New Member

I have events that are performance metrics taken over time. It includes fields like the sample value and object it pertains to. I want to display a table with that object and the most recent sample value for each object. Right now a query that shows all values would look something like this:

index=custom | table _time, account, metric_name, metric_value

I would like to do a query like

index=custom metric_name=utilization | blah blah

and get a table that includes account, metricname, metricvalue, time, but only show the most recent value for each account/metric_name.

Tags (2)
0 Karma
Highlighted

Re: How do you get a table of most recent events with multiple fields?

Influencer

you can do this

index=custom| stats latest(_time) as _time,  latest(metric_value) as metric_value by account metric_name
0 Karma