Splunk Search

How to get the Max out of row and field name of the max value

sangs8788
Communicator

Hi,

I have below resultset in place.

Screenshot 2020-11-30 at 4.35.38 PM.png

How do I get the Max by row and the Month when the Max happened. Something like below result

ModuleMonth when Max occuredMax Value
AppSDKAug-20204.21
CommentsAug-20200.10
ControlCenterJan-20200.72

 

Thanks

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Working with what you have (although it might be slightly easier to change your chart command first)

| untable Module _time count
| sort Module -count
| streamstats count as row by Module 
| where row=1 
| fields - row

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Working with what you have (although it might be slightly easier to change your chart command first)

| untable Module _time count
| sort Module -count
| streamstats count as row by Module 
| where row=1 
| fields - row
0 Karma

sangs8788
Communicator

Thanks it worked

 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...