Splunk Search

Query should return last/latest available data when there is no data for the selected time range

saichandjawari
Explorer

Query should return last/latest available data when there is no data for the selected time range

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Essentially, data is returned from the selected time range, if there is no data, what time range do you want to use?

You could do something like this

 

<your search>
| appendpipe
  [| stats count as _count
   | where _count = 0
   | where isnull(_count)
   | append
     [| search <your index> [| metasearch index=<your index> earliest=0
                             | head 1
                             | rename _time as earliest
                             | fields earliest]
      ]
   ]

 

0 Karma

saichandjawari
Explorer

The query is used in a dashboard panel as a statistical table with single row.  the data is usually  not available on regular intervals. Hence we would like to show the last available data instead of “no results found” when there is no data for the selected default time range that we have set.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK, so have you tried what I suggested?

0 Karma

saichandjawari
Explorer

Thanks for your response.

0 Karma

saichandjawari
Explorer

Yes, but that isn’t working. 

So here is a solution that I came up with — 


Step 1 - first write your results to a lookup file. 

<your query> |outputlookup yourlookup.csv

 

Step 2 - use that lookup in the query as shown below:

 

<your query> |append [|inputlookup yourlookup.csv 

|outputlookup yourlookup.csv override_if_empty = false create_empty = false]

 

the above query writes the results and stores in yourlookup.csv with wider time range. And  we are rewriting the stored results to the same lookupfile. In the last line override and Create_empty commands will make sure it will not give empty results. 
Note: use |dedup in the last if you see any duplicate results.

step 3- Create a saved search with this query and schedule it according to your requirement. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...