Splunk Search

Search to display the first instance of a particular field

New Member

I have a search which extracts some values into a table including the date. For one of the fields, e.g. src_ip, I want to show the first date that that value (a particular ip address) was seen. All the stats functions I have tried seem to aggregate the values. Is there a way to do what i want? Thanks

0 Karma

SplunkTrust
SplunkTrust

... | stats earliest(_time) by src_ip

0 Karma