Splunk Search

How to format table for resolved record after comparing two timestamp

Path Finder

Hi Friends,

My data set as below

ID    Date
1      01/01/2010
1      01/02/2010
2      01/01/2010
3      01/01/2010
3      01/02/2010
1      01/03/2010
4      01/02/2010
4      01/03/2010

Looking for the table with the data

Date           Count    Fixed
01/01/2010     3        1
01/02/2010     3        1
01/03/2010     2        0  

Regards.

0 Karma

Influencer

what is column Fixed here?

0 Karma

Path Finder

@vijeta - When record get closed earlier date then it will not be visible on next date so If the id is not available in the next date then that record has been considered to be fixed.

0 Karma

SplunkTrust
SplunkTrust

@ninadbhaskarwar what is the criteria for identifying fixed?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Path Finder

If the id is not available in the next date then that record has been fixed.

0 Karma