Splunk Search

Last event grouped by

oscargarcia
Path Finder

Hi,

I am building an app for managing some network switches. One of the views I want to create has the same data list:

For a given period of time, grouped by host, the date of the last event that matches certain criteria.

I can do that easily with "| tail 1", but that only covers one host or query. With the stats command, I can easily find the number of events matched grouped by host, but I am struggling to find the last one only for every host.

Any ideas?

Many thanks!

1 Solution

mw
Splunk Employee
Splunk Employee

How about:

... | stats last(_raw) by host

View solution in original post

mw
Splunk Employee
Splunk Employee

How about:

... | stats last(_raw) by host

Ayn
Legend

dedup host

0 Karma

YisroelB
Explorer

It seems that once you do this you lose access to the fields and would have to parse it out manually. For example if you pipe the above to "| table _time" _time is empty. Any way around this?

0 Karma

oscargarcia
Path Finder

so elegant... I love it... thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...