Splunk Search

Retrieve all latest rows that share the same _time value?

HappyFeet
Engager

I have an application that sends logs to Splunk every few seconds. These logs are "snapshots" which provide a static view of the system at the time they were taken/sent to Splunk.

I am attempting to get the latest rows from Splunk and present them in a table. Latest rows are determined by _time.

In the example below I want to retrieve the two last rows because they have the highest _time value.

Any help would be appreciated.

_time Name Status
9/28/22
8:14:08.968 PM
SPID 1 Queued
9/28/22
8:14:08.968 PM
SPID 2 Started
9/28/22
8:14:08.968 PM
SPID 3 Failing
9/28/22
8:14:12.968 PM
SPID 1 Started
9/28/22
8:14:12.968 PM
SPID 2 Started

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

There may be several ways to do that, but here's the first one I thought of.

<<your current search>>
| eventstats max(_time) as max_time
| where _time=max_time
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

There may be several ways to do that, but here's the first one I thought of.

<<your current search>>
| eventstats max(_time) as max_time
| where _time=max_time
---
If this reply helps you, Karma would be appreciated.

HappyFeet
Engager

I tried doing something similar with eventstats by counting the number events and grouping by _time to return all events that share the same count but it was not working as I wanted it to.

Thank you. That's surprisingly simple

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...