Splunk Search

Using "stats max(foo)", is it possible to get the whole line of the log that contains the max value of foo?

viggor
Path Finder

When I use | stats max(foo) I get the largest value of foo.

Is it possible to get the whole line of the log which contain this largest value?

0 Karma
1 Solution

sundareshr
Legend

Try like this

... | eventstats max(foo) as maxfoo | where foo=maxfoo | table _raw foo

View solution in original post

0 Karma

sundareshr
Legend

Try like this

... | eventstats max(foo) as maxfoo | where foo=maxfoo | table _raw foo
0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...