Splunk Search

How to create a data summary panel containing the host and the date of its last update?

nidet
Explorer

I want to make a panel that contains the host and the date of the last update, such as shown in the link. I used this, but I cannot place the date at the end in results.
host, count (sparkline), last update

host="*" | stats sparkline count by host

https://www.dropbox.com/s/kk4xpbdv290r1jj/splunk.JPG?dl=0

0 Karma
1 Solution

fdi01
Motivator

TRY LIKE THIS:
host="*" | stats sparkline count latest(_time) as "Last Update" by host| fieldformat "Last Update"=strftime('Last Update', "%c")

View solution in original post

fdi01
Motivator

TRY LIKE THIS:
host="*" | stats sparkline count latest(_time) as "Last Update" by host| fieldformat "Last Update"=strftime('Last Update', "%c")

martin_mueller
SplunkTrust
SplunkTrust

Use latest(_time) as "Last Update" in your stats.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That's an epoch timestamp which needs to be formatted for displaying to humans.

nidet
Explorer

Hi, Martin
Thanks for you answer is good. but i have large numbers in last update: 1427301579

host="*" | stats sparkline count latest(_time) as "Last Update" by host

would have to add another command or have an idea that I can investigate to solve the number?

Thanks, Martin

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...