Splunk Search

Using "stats max(foo)", is it possible to get the whole line of the log that contains the max value of foo?

Path Finder

When I use | stats max(foo) I get the largest value of foo.

Is it possible to get the whole line of the log which contain this largest value?

0 Karma
1 Solution

Legend

Try like this

... | eventstats max(foo) as maxfoo | where foo=maxfoo | table _raw foo

View solution in original post

0 Karma

Legend

Try like this

... | eventstats max(foo) as maxfoo | where foo=maxfoo | table _raw foo

View solution in original post

0 Karma