Splunk Search

How to format table for resolved record after comparing two timestamp

ninadbhaskarwar
Path Finder

Hi Friends,

My data set as below

ID    Date
1      01/01/2010
1      01/02/2010
2      01/01/2010
3      01/01/2010
3      01/02/2010
1      01/03/2010
4      01/02/2010
4      01/03/2010

Looking for the table with the data

Date           Count    Fixed
01/01/2010     3        1
01/02/2010     3        1
01/03/2010     2        0  

Regards.

0 Karma

Vijeta
Influencer

what is column Fixed here?

0 Karma

ninadbhaskarwar
Path Finder

@vijeta - When record get closed earlier date then it will not be visible on next date so If the id is not available in the next date then that record has been considered to be fixed.

0 Karma

niketn
Legend

@ninadbhaskarwar what is the criteria for identifying fixed?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

ninadbhaskarwar
Path Finder

If the id is not available in the next date then that record has been fixed.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...