Splunk Search

if multiple events at different time, only return most recent events based on a field

salt87
Engager

Hi,

I've got a search that returns me the following results:

Basically, I would like to only keep the most recent events for an IPAddress IF the field IPAddress has multiple events at 2 different time and discard the oldest event. In the case of the screenshot above, I would like to remove the highlighted line.

Would that be possible? Let me know if you need more information.

Thanks

Tags (1)
0 Karma

woodcock
Esteemed Legend

Add this to the bottom of your existing search:

... | streamstats count BY _time IPAddress
| where count == 1
0 Karma

woodcock
Esteemed Legend

Just add this to the bottom:

... | dedup IPAddress
0 Karma

salt87
Engager

Hi,

This won't work because I still need to see all events for an IPAddress. This will only show me one event per IP.

0 Karma

woodcock
Esteemed Legend

See my new answer.

0 Karma

arjunpkishore5
Motivator

Base on the example you provided

| stats values(pluginID) as pluginID by _time, IPAddress delim=","
| slats latest(pluginID) as pluginID, max(_time) as _time by IPAddress
| eval pluginID=split(pluginID,",")
| mvexpand pluginID 
0 Karma

salt87
Engager

Hi,

Unfortunately this is not working as it only shows one event for IP3 and not 2 events as shown in the OP screenshot.

This is the output:
IPAddress pluginID _time
IP1 94932 2019-11-01 04:19:23
IP2 46172 2019-11-08 20:32:25
IP3 108797 2019-10-31 02:00:21

What I would like is still keep both events for IP3 as per below:

IPAddress pluginID _time
IP1 94932 2019-11-01 04:19:23
IP2 46172 2019-11-08 20:32:25
IP3 108797 2019-10-31 02:00:21
IP3 84729 2019-10-31 02:00:21

Thanks

0 Karma

arjunpkishore5
Motivator

looks like latest is converting the mv field to a single value. Edited my answer. Please give it a try.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...