Splunk Search

How to format table for resolved record after comparing two timestamp

ninadbhaskarwar
Path Finder

Hi Friends,

My data set as below

ID    Date
1      01/01/2010
1      01/02/2010
2      01/01/2010
3      01/01/2010
3      01/02/2010
1      01/03/2010
4      01/02/2010
4      01/03/2010

Looking for the table with the data

Date           Count    Fixed
01/01/2010     3        1
01/02/2010     3        1
01/03/2010     2        0  

Regards.

0 Karma

Vijeta
Influencer

what is column Fixed here?

0 Karma

ninadbhaskarwar
Path Finder

@vijeta - When record get closed earlier date then it will not be visible on next date so If the id is not available in the next date then that record has been considered to be fixed.

0 Karma

niketn
Legend

@ninadbhaskarwar what is the criteria for identifying fixed?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

ninadbhaskarwar
Path Finder

If the id is not available in the next date then that record has been fixed.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...