Splunk Search

How to display latest value of CSV file?

Path Finder


I want to display last value of CSV file.
i am displaying max power usage with query:

index="test" sourcetype="power_test" | chart max(Power_consumption) as Max over host | sort 10 -max(Power_consumption)

This query will display two columns host and max(Power_consumption). i want to display one more column of latest power consumption by host.

What i need to add in my query?

Thanks in advance.


Tags (1)
0 Karma

index="test" sourcetype="power_test" | stats max(Power_consumption) as Max first(Power_consumption) as Recent by host
0 Karma