Splunk Search

How to delete last row in a table?

Kirthika
Path Finder
Count error_manager
1 System
2 System
3 System
4 System
5 System
6 System

 

How to delete last row in a table? 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Based on the layout, I hypothesize that the count column is in ascending order.  If it is so, find the maximum then compare each row with it.

| eventstats max(Count) as maxcount
| where Count < maxcount
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Note the use of lowercase for the count field - if this clashes with your existing field names use alternative names e.g. streamstats count as row etc.

| streamstats count
| eventstats count as total
| where count != total
| fields - count total
0 Karma

BrodyT
Loves-to-Learn

@Kirthika 

This will eliminate the last result assuming your data is in descending order of Count

| makeresults 
``` Replicating your results ```
| eval Count="1,2,3,4,5,6" 
| eval Count=split(Count,",") 
| mvexpand Count 
| eval error_manager = "System"
| table Count error_manager
``` excluding or "deleting" 6 ```
|eventstats
|eval LastCount = 'max(Count)'
|where 'Count'!='LastCount'
|table Count error_manager

 

0 Karma

BrodyT
Loves-to-Learn

Hi @Kirthika , In order to remove 6 from the table we must exclude it, this could be done using either |where or |search , here's my example using search:

| makeresults
``` Replicating your results ```
| eval Count="1,2,3,4,5,6"
| eval Count=split(Count,",")
| mvexpand Count
| eval error_manager = "System"
| table Count error_manager
``` excluding or "deleting" 6 ```
|search NOT Count = 6

Counterror_manager
1System
2System
3System
4System
5System



0 Karma

Kirthika
Path Finder

We need to remove last row. It shouldn't be based on value.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...