Splunk Search

How to display latest value of CSV file?

geetanjali
Path Finder

Hello,

I want to display last value of CSV file.
i am displaying max power usage with query:

index="test" sourcetype="power_test" | chart max(Power_consumption) as Max over host | sort 10 -max(Power_consumption)

This query will display two columns host and max(Power_consumption). i want to display one more column of latest power consumption by host.

What i need to add in my query?

Thanks in advance.

Geetanjali

Tags (1)
0 Karma

ziegfried
Influencer
index="test" sourcetype="power_test" | stats max(Power_consumption) as Max first(Power_consumption) as Recent by host
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...