Splunk Search

how to show most recent value of "status" field for each server by group

benjamincortega
New Member

With log data as such:

date_time server=server1 group=group1 status=statusA
date_time server=server2 group=group1 status=statusA
date_time server=server3 group=group1 status=statusA
date_time server=server4 group=group1 status=statusA
date_time server=server1 group=group2 status=statusA
date_time server=server2 group=group2 status=statusA
date_time server=server3 group=group2 status=statusA
date_time server=server7 group=group2 status=statusA
date_time server=server1 group=group1 status=statusB
date_time server=server2 group=group1 status=statusB
date_time server=server3 group=group1 status=statusB
date_time server=server1 group=group2 status=statusB
date_time server=server2 group=group2 status=statusB

I’d like to be able to show a table of results that look like this:

group1 server1 statusB
.............server2 statusB
.............server3 statusB
.............server4 statusA
group2 server1 statusB
.............server2 statusB
.............server3 statusA
.............server7 statusA

The table should show all groups that appear in the log, and under each group it should list all servers that are associated with that group along with the most recent status for each of those servers in that particular group.

Tags (3)
0 Karma

sbbadri
Motivator

Hi,

Please try this,

.... | eval co = server."". status | stats values(co) as server_status by group | rex field=server_status "(?P\S+)(?P\S+)" | fields - server_status

0 Karma

adonio
Ultra Champion

.... | stats latest(status) by server group

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...