Splunk Search

Using subsearches to get highest value

Builder

Hello,
I have a search that tables certain values from my data fields, although i wish to create a new field on all events called Maximum that gets the latest value of a field called max and another called min

Tags (2)
1 Solution

Splunk Employee
Splunk Employee

You can use eventstats:

index=internal | eventstats max(datesecond) AS MAX min(datesecond) as MIN | table datesecond,MAX,MIN

View solution in original post

Splunk Employee
Splunk Employee

You can use eventstats:

index=internal | eventstats max(datesecond) AS MAX min(datesecond) as MIN | table datesecond,MAX,MIN

View solution in original post

Builder

Hi mzorzi,

Thanks for your response.

I used eventstats but I also wanted to get values from the search and table them as well.
Do you know how?

0 Karma

SplunkTrust
SplunkTrust

Could you provide the search and if possible some sample data?

0 Karma