Splunk Search

Trying to determine min/max date/time for a list of ip addresses


My search returns a table of a count of ip addresses that have hit our system in a given search period. I am trying to determine what the earliest time and most recent time was for each ip address.

index=myIndex  host=mySrvr sourcetype=mysource | stats count by s_ipad, r_ip_country,  |Fields s_ipad, r_ip_country. min(_time),max(_time) count | search count>=15 |sort -count

The table of data returns the top 15 ip address and country of origin, however the min(_time) and max(_time) are empty. Any help would be appreciated.


Labels (1)
Tags (2)
0 Karma
1 Solution


This may help...

index=myIndex  host=mySrvr sourcetype=mysource | stats count,min(_time),max(_time) by s_ipad, r_ip_country | search count>=15  |sort -count

View solution in original post

0 Karma


Hello Sir,

Based on the topic, I am trying to fetch the first time and the last time an error occurred in application logs, and thus used following query: -

index="dummy" (search condition) |rex ...(?<error>.*?)...|stats count, min(_time), max(_time) by error

I got for columns in results: error, count, min(_time) and max(_time).

However, in column min(_time) and max(_time) I am getting values like: -
1631484056.103, 1631501959.541 respectively.

Thus, I need your help to convert results of the two columns in readable format.

Thank you

0 Karma


This may help...

index=myIndex  host=mySrvr sourcetype=mysource | stats count,min(_time),max(_time) by s_ipad, r_ip_country | search count>=15  |sort -count

0 Karma


Search query worked perfect. Thank you.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...