Splunk Search

mvfind for the last value

pkashou
Explorer

It seems that mvfind will only return the index of the first matching value. I would like to return the index of the last matching value within an MV field. Thanks!

Tags (1)
0 Karma

pkashou
Explorer

I found the answer. I create a MV field for just the value I am interested in, determine the total count, and then return the value at the index of count-1.

eval txKV = mvfilter(match(kvPair, "tx_success")) |
eval txCount = mvcount(txKV) |
eval txTime = mvindex(txKV, txCount-1) |
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...