Splunk Search

use subsearch

Communicator

hi every one,

I want to make a search that could give me the same result of SQL Querie

select id_product from products where price = (
select max price from products )

thank you

0 Karma
1 Solution

Esteemed Legend

sourcetype=products | eventstats max(price) AS maxPrice | where price=maxPrice | stats values(idproduct)
OR
sourcetype=products | eventstats max(price) AS maxPrice | where price=maxPrice | fields id
product

View solution in original post

0 Karma

Esteemed Legend

sourcetype=products | eventstats max(price) AS maxPrice | where price=maxPrice | stats values(idproduct)
OR
sourcetype=products | eventstats max(price) AS maxPrice | where price=maxPrice | fields id
product

View solution in original post

0 Karma

Communicator

thank you woodcock
it works perfectly. have a nice day

0 Karma