Splunk Search

Stats command with latest values listing

jerinvarghese
Communicator

Hi Team,

 

I have a splunk query that am testing for Service Now data extract.

 

index=snow "INC783"
| search dv_state="In Progress" OR dv_state="New" OR dv_state="On Hold"
| stats max(_time) as Time latest(dv_state) as State by number, dv_priority
| fieldformat Time=strftime(Time,"%Y-%m-%d %H:%M:%S")
| table number,Time, dv_priority, State

 

 

The challenge with the code is, above output is listing all the states for the particular Incidnet, even when i tried to filter for only the latest and max time.

numberTimedv_priorityState
INC7832024-11-13 16:56:141 - CriticalIn Progress
INC7832024-11-13 17:00:033 - ModerateOn Hold

 

The data must only show the latest one, which must be the one with "On Hold".
Tried multiple method, but failing and showing all.
how can i achieve it.

 

thanks

Jerin V

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Your by clause also include dv_priority which is why you are getting multiple results for an incident. Try something like this

index=snow "INC783"
| search dv_state="In Progress" OR dv_state="New" OR dv_state="On Hold"
| stats max(_time) as Time latest(dv_state) as State latest(dv_priority) as Priority by number
| fieldformat Time=strftime(Time,"%Y-%m-%d %H:%M:%S")
| table number,Time, Priority, State

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Your by clause also include dv_priority which is why you are getting multiple results for an incident. Try something like this

index=snow "INC783"
| search dv_state="In Progress" OR dv_state="New" OR dv_state="On Hold"
| stats max(_time) as Time latest(dv_state) as State latest(dv_priority) as Priority by number
| fieldformat Time=strftime(Time,"%Y-%m-%d %H:%M:%S")
| table number,Time, Priority, State
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...