Splunk Search
Highlighted

Opposite of "head" ?

Champion

I'm trying to find out what the oldest occurrence of an event was - as in, opposite of head. Is there such a command?

I've tried using " * | reverse | head 1 " which works but is very slow and inefficient.

Tags (1)
Highlighted

Re: Opposite of "head" ?

Splunk Employee
Splunk Employee

i tried that, and then i tried * | sort -_time and this seems to be faster. I am unaware of a command that is the opposite of head...

0 Karma
Highlighted

Re: Opposite of "head" ?

Splunk Employee
Splunk Employee

| sort _time, that is, no - sign...

0 Karma
Highlighted

Re: Opposite of "head" ?

Builder
Highlighted

Re: Opposite of "head" ?

Splunk Employee
Splunk Employee

tail fail tail fail

0 Karma
Highlighted

Re: Opposite of "head" ?

Splunk Employee
Splunk Employee

awesome awesome awesome!!!

0 Karma
Highlighted

Re: Opposite of "head" ?

Champion

w00t!!!!!!!!!!!

0 Karma