Splunk Search

SPL

SN1
Path Finder

| makeresults
| eval sourcetype=split("BBCN-Kunshan,BSCN-Suzhou,BBSP-Malasiya,BTCN-Tianjin,BXCN-Xian,BCCN-Suzhouheadquarters,BCIT-Italy", ",")
| mvexpand sourcetype
| eval index="bbs-firewall"
| join type=left index sourcetype
[ | tstats count
where index="bbs-firewall" earliest=-24h
by index sourcetype ]
| eval count=coalesce(count, 0)
| where count=0
| stats values(sourcetype) as sourcetypes by index
| eval message ="Sourcetypes With 0 Events Last 24hr"
| table index sourcetypes message

this is the search that shows which sourcetype is having 0 events last 24 hr . Now i also wanted to show the time of the last log that came in splunk .

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Adding to @richgalloway 's remarks about your problem being incorrectly formulated (maybe you wanted something else but didn't word it properly), this is a very badly used join command. As a rule of thumb the join command is to be avoided whenever possible.

Your search can be equally well rewritten without it.

Oh, and if you limit yourself to just one index with tstats' where condition there's no point of adding index to the by clause.

So effectively your initial search might be swapped around and rewritten as

| tstats count where index="bbs-firewall" earliest=-24h by sourcetype
| append
   [ |  makeresults
| eval sourcetype=split("BBCN-Kunshan,BSCN-Suzhou,BBSP-Malasiya,BTCN-Tianjin,BXCN-Xian,BCCN-Suzhouheadquarters,BCIT-Italy", ",")
| mvexpand sourcetype
| eval count=0 ]
| stats sum(count) as count by sourcetype
| ...

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If there were no events in the last 24 hours then there is no last timestamp to display.

The only way to get the timestamp would be to join the current search with one that scans the logs for the most recent entry for each sourcetype in some larger time window (perhaps 30 days).

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...