Splunk Search

using stats function to return latest value but need associated timestamp of that value

erhksadhwani
New Member

stats latest(sequence)returns the latest sequence number but I need to display the associated timestamp when the sequence number was received.

Tags (1)
0 Karma

rjthibod
Champion

just add latest(_time) as _time

stats latest(_time) as _time latest(sequence)

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...