Splunk Search

Is there another way to use min max?

karu0711
Communicator

I am running search.
basesearch  |eventstats count values(date) as Date by ID 

result I get count 2 or 3 or 1
how do I get count=1 OR count=3. 
how I use max(count)  and min(count). 
I need this because min(count) will new data and max(count) will old data. 
Is there any other way to do this?

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Perhaps you mean streamstats to number the events which would normally be in reverse chronological order i.e. newest first?

basesearch
| streamstats count by ID

karu0711
Communicator

but I want only output new finding separate table and old in separate table. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

For new use:

basesearch
| streamstats count by ID
| where count == 1

For old use:

basesearch
| streamstats count by ID
| eventstats max(count) as last by ID
| where count == last
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...