Splunk Search

How to create a data summary panel containing the host and the date of its last update?

nidet
Explorer

I want to make a panel that contains the host and the date of the last update, such as shown in the link. I used this, but I cannot place the date at the end in results.
host, count (sparkline), last update

host="*" | stats sparkline count by host

https://www.dropbox.com/s/kk4xpbdv290r1jj/splunk.JPG?dl=0

0 Karma
1 Solution

fdi01
Motivator

TRY LIKE THIS:
host="*" | stats sparkline count latest(_time) as "Last Update" by host| fieldformat "Last Update"=strftime('Last Update', "%c")

View solution in original post

fdi01
Motivator

TRY LIKE THIS:
host="*" | stats sparkline count latest(_time) as "Last Update" by host| fieldformat "Last Update"=strftime('Last Update', "%c")

martin_mueller
SplunkTrust
SplunkTrust

Use latest(_time) as "Last Update" in your stats.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That's an epoch timestamp which needs to be formatted for displaying to humans.

nidet
Explorer

Hi, Martin
Thanks for you answer is good. but i have large numbers in last update: 1427301579

host="*" | stats sparkline count latest(_time) as "Last Update" by host

would have to add another command or have an idea that I can investigate to solve the number?

Thanks, Martin

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...